Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000216574


DSA-2023-279: Security Update for Dell SupportAssist for Business PCs Vulnerability

Summary: In Dell SupportAssist for Business PCs with the SupportAssist User Interface available, a locally authenticated user can bypass authentication and exclusively utilize the "Run as Administrator" component on the respective PC to perform driver scans and installations without acquiring any additional administrator privileges. This temporary privilege self-expires after 15 minutes. ...

Article Content


Impact

Medium

Details

Proprietary Code CVEs

Description

CVSS Base Score

CVSS Vector String

CVE-2023-39249 Dell SupportAssist for Business PCs version 3.4.0 contains a local Authentication Bypass vulnerability that allows locally authenticated non-admin users to gain temporary privilege within the SupportAssist User Interface on their respective PC. The Run as Admin temporary privilege feature enables IT/System Administrators to perform driver scans and Dell-recommended driver installations without requiring them to log out of the local non-admin user session. However, the granted privilege is limited solely to the SupportAssist User Interface and automatically expires after 15 minutes. 6.3 (Medium) CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

Proprietary Code CVEs

Description

CVSS Base Score

CVSS Vector String

CVE-2023-39249 Dell SupportAssist for Business PCs version 3.4.0 contains a local Authentication Bypass vulnerability that allows locally authenticated non-admin users to gain temporary privilege within the SupportAssist User Interface on their respective PC. The Run as Admin temporary privilege feature enables IT/System Administrators to perform driver scans and Dell-recommended driver installations without requiring them to log out of the local non-admin user session. However, the granted privilege is limited solely to the SupportAssist User Interface and automatically expires after 15 minutes. 6.3 (Medium) CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

CVEs Addressed

Product

Software/Firmware

Affected Versions

Remediated Versions

Link

 CVE-2023-39249 SupportAssist for Business PCs  Software 3.4.0 3.4.1   https://www.dell.com/support/home/en-us/product-support/product/supportassist-business-pcs/

CVEs Addressed

Product

Software/Firmware

Affected Versions

Remediated Versions

Link

 CVE-2023-39249 SupportAssist for Business PCs  Software 3.4.0 3.4.1   https://www.dell.com/support/home/en-us/product-support/product/supportassist-business-pcs/

Workarounds and Mitigations

CVE ID Workaround and Mitigation
CVE-2023-39249 Users need to keep the SupportAssist Business PCs updated to the latest version.

Revision History

 

RevisionDateDescription
1.02023-08-08Initial Release

 

Related Information


Article Properties


Affected Product

SupportAssist, SupportAssist for Business PCs

Last Published Date

08 Aug 2023

Version

1

Article Type

Dell Security Advisory