PT-2021-21204 · Microsoft+1 · Windows+1
Ammarit Thongthua
+2
·
Published
2021-09-28
·
Updated
2022-10-25
·
CVE-2021-36286
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell SupportAssist Client Consumer versions 3.9.13.0 and any versions prior to 3.9.13.0
Description
The issue concerns an arbitrary file deletion vulnerability that can be exploited using the Windows feature of NTFS called Symbolic links. Symbolic links can be created by any non-privileged user under some object directories. However, combining them with a different object, such as the NTFS junction point, allows for the exploitation. The SupportAssist clean files functionality does not distinguish junction points from the physical folder and proceeds to clean the target of the junction, allowing non-privileged users to create junction points and delete arbitrary files on the system that can be accessed only by the admin.
Recommendations
For Dell SupportAssist Client Consumer versions 3.9.13.0 and any versions prior to 3.9.13.0, consider disabling the clean files functionality until a patch is available to prevent non-privileged users from deleting arbitrary files on the system. Restrict access to the NTFS junction point to minimize the risk of exploitation. Avoid using the SupportAssist clean files functionality in environments where non-privileged users have access to the system. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Link Following
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dell Supportassist Client Consumer
Windows