PT-2021-21204 · Microsoft+1 · Windows+1

Ammarit Thongthua

+2

·

Published

2021-09-28

·

Updated

2022-10-25

·

CVE-2021-36286

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell SupportAssist Client Consumer versions 3.9.13.0 and any versions prior to 3.9.13.0
Description The issue concerns an arbitrary file deletion vulnerability that can be exploited using the Windows feature of NTFS called Symbolic links. Symbolic links can be created by any non-privileged user under some object directories. However, combining them with a different object, such as the NTFS junction point, allows for the exploitation. The SupportAssist clean files functionality does not distinguish junction points from the physical folder and proceeds to clean the target of the junction, allowing non-privileged users to create junction points and delete arbitrary files on the system that can be accessed only by the admin.
Recommendations For Dell SupportAssist Client Consumer versions 3.9.13.0 and any versions prior to 3.9.13.0, consider disabling the clean files functionality until a patch is available to prevent non-privileged users from deleting arbitrary files on the system. Restrict access to the NTFS junction point to minimize the risk of exploitation. Avoid using the SupportAssist clean files functionality in environments where non-privileged users have access to the system. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Link Following

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2021-36286

Affected Products

Dell Supportassist Client Consumer
Windows