Vulnerabilities > CVE-2019-3719 - Unspecified vulnerability in Dell Supportassist
Attack vector
ADJACENT_NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
Dell SupportAssist Client versions prior to 3.2.0.90 contain a remote code execution vulnerability. An unauthenticated attacker, sharing the network access layer with the vulnerable system, can compromise the vulnerable system by tricking a victim user into downloading and executing arbitrary executables via SupportAssist client from attacker hosted sites.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Windows |
NASL id | DELL_SUPPORT_ASSIST_DSA-2019-051.NASL |
description | The Dell SupportAssist Client versions prior to 3.2.0.90, installed on the remote Windows host reportedly is affected by multiple vulnerabilities : - An improper origin validation vulnerability exist in Dell SupportAssist Client versions prior to 3.2.0.90. An unauthenticated remote attacker could potentially exploit this vulnerability to attempt CSRF attacks on users of the impacted systems. (CVE-2019-3718). Dell SupportAssist Client versions prior to 3.2.0.90 contain a remote code execution vulnerability. - A remote code execution vulnerability exist in Dell SupportAssist Client versions prior to 3.2.0.90. An unauthenticated attacker, sharing the network access layer with the vulnerable system, can compromise the vulnerable system by tricking a victim user into downloading and executing arbitrary executables via SupportAssist client from attacker hosted sites. (CVE-2019-3719). |
last seen | 2020-06-13 |
modified | 2020-06-12 |
plugin id | 137364 |
published | 2020-06-12 |
reporter | This script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/137364 |
title | Dell SupportAssist Multiple Vulnerabilities (DSA-2019-051) |
code |
|
The Hacker News
id | THN:054397C4930B4A2C6545A8B59C7343A4 |
last seen | 2019-05-02 |
modified | 2019-05-02 |
published | 2019-05-02 |
reporter | The Hacker News |
source | https://thehackernews.com/2019/05/dell-computer-hacking.html |
title | Pre-Installed Software Flaw Exposes Most Dell Computers to Remote Hacking |