Podatność CVE-2021-36297


Publikacja: 2021-09-28   Modyfikacja: 2021-09-29

Opis:
SupportAssist Client version 3.8 and 3.9 contains an Untrusted search path vulnerability that allows attackers to load an arbitrary .dll file via .dll planting/hijacking, only by a separate administrative action that is not a default part of the SOSInstallerTool.exe installation for executing arbitrary dll's,

Typ:

CWE-426

(Untrusted Search Path)

 Referencje:
https://www.dell.com/support/kbdoc/en-us/000191057/dsa-2021-163-dell-supportassist-client-consumer-security-update-for-two-vulnerabilities

Copyright 2022, cxsecurity.com

 

Back to Top