PT-2024-12065 · Dell · Dell Supportassist

Jaeheng Yoon

·

Published

2024-02-14

·

Updated

2024-10-17

·

CVE-2023-25535

CVSS v3.1

7.2

High

VectorAV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell SupportAssist for Home PCs Installer Executable versions prior to 3.13.2.19
Description The issue affects the initial installation of Dell SupportAssist for Home PCs and can result in local privilege escalation (LPE). This vulnerability only affects first-time installations done prior to 8th March 2023.
Recommendations For versions prior to 3.13.2.19, update to version 3.13.2.19 or later to resolve the issue. As a temporary workaround, consider restricting the use of the vulnerable installer until a patch is applied.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2023-25535

Affected Products

Dell Supportassist