PT-2024-12785 · Dell · Dell Supportassist
Published
2024-02-14
·
Updated
2024-10-17
·
CVE-2023-39249
CVSS v3.1
6.3
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Dell SupportAssist for Business PCs version 3.4.0
Description
The issue allows locally authenticated non-admin users to gain temporary privilege within the SupportAssist User Interface on their respective PC. The Run as Admin temporary privilege feature enables IT/System Administrators to perform driver scans and Dell-recommended driver installations without requiring them to log out of the local non-admin user session. However, the granted privilege is limited solely to the SupportAssist User Interface and automatically expires after 15 minutes.
Recommendations
For Dell SupportAssist for Business PCs version 3.4.0, consider disabling the Run as Admin temporary privilege feature until a patch is available to prevent locally authenticated non-admin users from gaining temporary privilege within the SupportAssist User Interface.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Supportassist