This post is more than 5 years old
2 Posts
0
4815
April 9th, 2019 08:00
Dell Digital Delivery
I apologize if this is a duplicate. When I originally posted the message the website sent me back to a change-your-password page when I hit post, and apparently just discarded the post.
The customer support page is not working for me today, I hope someone here can help. My eight month old Inspiron 5676 recently started popping up a message saying I need to install Dell Digital Delivery Application. By the title, this does not sound like something I want or need to install. I found the software on this web site, plenty of information on version, dates, compatibility, but absolutely nothing about what is does and why I might want it on my computer.
So, can anyone tell my what this actually does, and whether it is necessary? Also, how to I get the pop ups to go away for good without installing the software. I assume that app that is generating the pop up also monitors for updates to legitimate drivers/software that I would like to be informed about. So I would rather not uninstall the monitoring app if there is a way to tell it to only watch for the important things.
Thanks in advance for any information and suggestions.


speedstep
11 Legend
•
47K Posts
1
April 9th, 2019 08:00
Dell Digital Delivery is an application that enables users to buy software for Dell computers. Applications that come pre-installed in the computer do not have discs or license keys. Dell Digital Delivery downloads and installs purchased software to the computer.
The popup is related to the package fixes to address privilege escalation vulnerability CVE-2018-11072
https://www.dell.com/support/article/SLN313559
https://downloads.dell.com/FOLDER05073855M/3/Dell-Digital-Delivery-Application_C3JKT_WIN_3.5.2000.0_A00.EXE
CVE Identifier: CVE-2018-11072
Severity: High
Affected Products:
Summary:
Dell Digital Delivery contains a fix for DLL Injection Vulnerability that could potentially be exploited by malicious users to compromise the affected system.
Details:
Dell Digital Delivery versions prior to 3.5.1 contain a DLL Injection Vulnerability. A local authenticated malicious user with advance knowledge of the application workflow could potentially load and execute a malicious DLL with administrator privileges.
Resolution:
Dell Digital Delivery version 3.5.2 and later releases contain a resolution to this vulnerability.
Dell recommends all customers upgrade at the earliest opportunity.
Downloads for the applicable version are available below:
SpykeOne
2 Posts
0
April 9th, 2019 09:00
speedstep: Thank you for your quick and comprehensive response. It is helpful, I will update the software.
I still have secondary questions I would like thoughts on. I am not sure that I even want this software on my computer. If I do not need it, then deleting it is safer than updating it whenever someone discovers a security hole. I do not recall purchasing any software with my computer other than Windows (and Microsoft takes care of updating windows.) Can I tell what if any software apps DDD is managing for me? If there are none, and I delete DDD will that break the update monitor?