// Security NEWS // A Critical Flaw in a Software Supporting Tens of Millions of PCs

in #news5 years ago

A vulnerability in a PC-Doctor product allows you to take control of a machine. This software is distributed on Dell PCs under the name "SupportAssist". Fortunately, a patch is available.

Capture d’écran 2019-06-22 à 16.04.36.png

Source

If you have a Dell PC, update it immediately. A SafeBreach security researcher has found a critical flaw in the Dell SupportAssist support software that allows malware to take full control of the machine.

Indeed, one of the software components of this product does not securely load DLLs, does not specify a limit on the loading path and does not verify any signatures. An attacker can therefore quite easily introduce a poxed DLL and have it executed with system privileges.

Dell has already published a patch that needs to be installed. This flaw concerns both consumer and professional PCs. However, the American manufacturer is not the only one affected by this case.

Dell SupportAssist is actually a repackaging of the PC-Doctor solution. Those who use PC-Doctor Toolbox for Windows are therefore also concerned by this problem. According to PC-Doctor, this represents more than 100 million PCs worldwide.

Other vulnerable OEM solutions are in circulation, such as Corsair One Diagnostics, Corsair Diagnostics, Staples EasyTech Diagnostics, Tobii ISeries Diagnostic Tool and Tobii Dynavox Diagnostic Tool.

Credit: Dell would like to thank Peleg Hadar for reporting this vulnerability.

Severity Rating: For an explanation of Severity Ratings, refer to Dell’s Vulnerability Disclosure Policy. Dell EMC recommends all customers take into account both the base score and any relevant temporal and environmental scores which may impact the potential severity associated with particular security vulnerability.

Sources : SafeBreach and Dell

Stay Informed, Stay Safe

DQmdpsoEfLe5nRg4Q1oKWHNjLdMnAucCYfRou1yF5Yiwrzs.png

DQmNuF3L71zzxAyJB7Lk37yBqjBRo2uafTAudFDLzsoRV5L.gif

Sort:  

Congratulations @vijbzabyss! You have completed the following achievement on the Steem blockchain and have been rewarded with new badge(s) :

You distributed more than 6000 upvotes. Your next target is to reach 7000 upvotes.

You can view your badges on your Steem Board and compare to others on the Steem Ranking
If you no longer want to receive notifications, reply to this comment with the word STOP

To support your work, I also upvoted your post!

Do not miss the last post from @steemitboard:

The Steem community has lost an epic member! Farewell @woflhart!
SteemitBoard - Witness Update
Do not miss the coming Rocky Mountain Steem Meetup and get a new community badge!
Vote for @Steemitboard as a witness to get one more award and increased upvotes!

Coin Marketplace

STEEM 0.16
TRX 0.16
JST 0.031
BTC 58976.49
ETH 2502.14
USDT 1.00
SBD 2.48