CVE-2022-34387

Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privilege escalation vulnerability. A local authenticated malicious user could potentially exploit this vulnerability to elevate privileges and gain total control of the system.
References
Link Resource
https://www.dell.com/support/kbdoc/000204114 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:supportassist_for_business_pcs:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:supportassist_for_home_pcs:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:48

Type Values Removed Values Added
Summary Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privilege escalation vulnerability. A local authenticated malicious user could potentially exploit this vulnerability to elevate privileges and gain total control of the system. Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privilege escalation vulnerability. A local authenticated malicious user could potentially exploit this vulnerability to elevate privileges and gain total control of the system.

21 Feb 2023, 17:28

Type Values Removed Values Added
References (MISC) https://www.dell.com/support/kbdoc/000204114 - (MISC) https://www.dell.com/support/kbdoc/000204114 - Vendor Advisory
CPE cpe:2.3:a:dell:supportassist_for_home_pcs:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:supportassist_for_business_pcs:*:*:*:*:*:*:*:*
First Time Dell supportassist For Home Pcs
Dell supportassist For Business Pcs
Dell
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE CWE-668

11 Feb 2023, 01:23

Type Values Removed Values Added
New CVE

Information

Published : 2023-02-11 01:23

Updated : 2023-12-10 14:48


NVD link : CVE-2022-34387

Mitre link : CVE-2022-34387

CVE.ORG link : CVE-2022-34387


JSON object : View

Products Affected

dell

  • supportassist_for_home_pcs
  • supportassist_for_business_pcs
CWE
CWE-668

Exposure of Resource to Wrong Sphere

CWE-377

Insecure Temporary File