PT-2024-12785 · Dell · Dell Supportassist

Published

2024-02-14

·

Updated

2024-10-17

·

CVE-2023-39249

CVSS v3.1

6.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Dell SupportAssist for Business PCs version 3.4.0
Description The issue allows locally authenticated non-admin users to gain temporary privilege within the SupportAssist User Interface on their respective PC. The Run as Admin temporary privilege feature enables IT/System Administrators to perform driver scans and Dell-recommended driver installations without requiring them to log out of the local non-admin user session. However, the granted privilege is limited solely to the SupportAssist User Interface and automatically expires after 15 minutes.
Recommendations For Dell SupportAssist for Business PCs version 3.4.0, consider disabling the Run as Admin temporary privilege feature until a patch is available to prevent locally authenticated non-admin users from gaining temporary privilege within the SupportAssist User Interface.

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-39249

Affected Products

Dell Supportassist