Skip to main content

DSA-2024-470: Security Update for Dell SupportAssist for Home PCs and Dell SupportAssist for Business PCs vulnerabilities

Summary: Dell SupportAssist for Home and Business PCs Software remediation is available for local code execution vulnerability that could be exploited by malicious users to compromise that affected system only. ...

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

High

Details

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2024-52535 Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remediation component. A low-privileged authenticated user could potentially exploit this vulnerability, gaining privileges escalation, leading to arbitrary deletion of files and folders from the system. 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2024-52535 Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remediation component. A low-privileged authenticated user could potentially exploit this vulnerability, gaining privileges escalation, leading to arbitrary deletion of files and folders from the system. 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Product Affected Versions Remediated Versions Link
SupportAssist for Home PCs Versions prior to 4.6.2 Versions 4.6.2 or later https://www.dell.com/support/contents/article/product-support/self-support-knowledgebase/software-and-downloads/support-assist/supportassist-for-home
SupportAssist for Business PCs Versions prior to 4.5.1 Versions 4.5.1 or later https://www.dell.com/lp/dt/supportassist-business-PC
Product Affected Versions Remediated Versions Link
SupportAssist for Home PCs Versions prior to 4.6.2 Versions 4.6.2 or later https://www.dell.com/support/contents/article/product-support/self-support-knowledgebase/software-and-downloads/support-assist/supportassist-for-home
SupportAssist for Business PCs Versions prior to 4.5.1 Versions 4.5.1 or later https://www.dell.com/lp/dt/supportassist-business-PC

Revision History

RevisionDateDescription
1.02024-12-23Initial Release

Acknowledgements

Dell would like to thank mdanilor for reporting this issue. 

Related Information

Affected Products

SupportAssist, SupportAssist for Home PCs, SupportAssist for Business PCs
Article Properties
Article Number: 000261086
Article Type: Dell Security Advisory
Last Modified: 23 Dec 2024
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.