DSA-2022-139 - Dell SupportAssist for Home PCs and Business PCs Security Update for Multiple Security Vulnerabilities.
Summary: Dell SupportAssist for Home PCs and Business PCs remediation is available for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system. ...
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Impact
High
Details
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-29092 | Dell SupportAssist Client Consumer versions (3.11.0 and versions prior) and Dell SupportAssist Client Commercial versions (3.2.0 and versions prior) contain a privilege escalation vulnerability. A non-admin user can exploit the vulnerability and gain admin access to the system. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2022-29093 | Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion vulnerability. Authenticated non-admin user could exploit the issue and delete arbitrary files on the system. | 7.1 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
| CVE-2022-29094 | Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion/overwrite vulnerability. Authenticated non-admin user could exploit the issue and delete or overwrite arbitrary files on the system. | 7.1 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
| CVE-2022-29095 | Dell SupportAssist Client Consumer versions (3.10.4 and prior) and Dell SupportAssist Client Commercial versions (3.1.1 and prior) contain a cross-site scripting vulnerability. A remote unauthenticated malicious user could potentially exploit this vulnerability under specific conditions leading to execution of malicious code on a vulnerable system. | 8.3 | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-29092 | Dell SupportAssist Client Consumer versions (3.11.0 and versions prior) and Dell SupportAssist Client Commercial versions (3.2.0 and versions prior) contain a privilege escalation vulnerability. A non-admin user can exploit the vulnerability and gain admin access to the system. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2022-29093 | Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion vulnerability. Authenticated non-admin user could exploit the issue and delete arbitrary files on the system. | 7.1 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
| CVE-2022-29094 | Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion/overwrite vulnerability. Authenticated non-admin user could exploit the issue and delete or overwrite arbitrary files on the system. | 7.1 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
| CVE-2022-29095 | Dell SupportAssist Client Consumer versions (3.10.4 and prior) and Dell SupportAssist Client Commercial versions (3.1.1 and prior) contain a cross-site scripting vulnerability. A remote unauthenticated malicious user could potentially exploit this vulnerability under specific conditions leading to execution of malicious code on a vulnerable system. | 8.3 | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H |
Affected Products & Remediation
| CVEs Addressed | Product | Affected Versions | Updated Versions | Link to Update |
| CVE-2022-29092 | Dell SupportAssist for Home PCs | Version 3.11.0 and earlier | N/A | There are two ways in which the customer can get the latest component which has the fix:
|
| Dell SupportAssist for Business PCs | Version 3.2.0 and earlier | N/A | There are two ways in which the customer can get the latest component which has the fix:
|
|
| CVE-2022-29093, CVE-2022-29094, and CVE-2022-29095 | Dell SupportAssist for Home PCs | 3.10.4 and earlier | 3.11.4 | SupportAssist for Home PCs Release Notes and User Guide |
| Dell SupportAssist for Business PCs | 3.1.1 and earlier | 3.2.0 |
TechDirect Link for Admins Release Notes and User Guide |
NOTE: Version 3.11.3 also contains the fix, however, it is recommended that customers move to 3.11.4.
| CVEs Addressed | Product | Affected Versions | Updated Versions | Link to Update |
| CVE-2022-29092 | Dell SupportAssist for Home PCs | Version 3.11.0 and earlier | N/A | There are two ways in which the customer can get the latest component which has the fix:
|
| Dell SupportAssist for Business PCs | Version 3.2.0 and earlier | N/A | There are two ways in which the customer can get the latest component which has the fix:
|
|
| CVE-2022-29093, CVE-2022-29094, and CVE-2022-29095 | Dell SupportAssist for Home PCs | 3.10.4 and earlier | 3.11.4 | SupportAssist for Home PCs Release Notes and User Guide |
| Dell SupportAssist for Business PCs | 3.1.1 and earlier | 3.2.0 |
TechDirect Link for Admins Release Notes and User Guide |
NOTE: Version 3.11.3 also contains the fix, however, it is recommended that customers move to 3.11.4.
Revision History
| Revision | Date | Description |
| 1.0 | 2022-06-09 | Initial Draft |
| 1.1 | 2022-06-27 | Updated affected products and remediation section |
Acknowledgements
Dell would like to thank Molybdenum for reporting CVE-2022-29092 and Patrick Murphy for reporting CVE-2022-29093 and CVE-2022-29094.
Related Information
Legal Disclaimer
Affected Products
SupportAssist for Home PCs, SupportAssist for Business PCsProducts
Product Security InformationArticle Properties
Article Number: 000200456
Article Type: Dell Security Advisory
Last Modified: 19 Sept 2025
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.