CVE-2020-5316
Last modified
CVE-2020-5316 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Dell SupportAssist for Business PCs versions 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3 and Dell SupportAssist for Home PCs version 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3, 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, 3.2.1, 3.2.2, 3.3, 3.3.1, 3.3.2, 3.3.3, 3.4 contain an uncontrolled search path vulnerability. A locally authenticated low privileged user could exploit this vulnerability to cause the loading of arbitrary DLLs by the SupportAssist binaries, resulting in the privileged execution of arbitrary code.. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
Dell SupportAssist for Business PCs versions 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3 and Dell SupportAssist for Home PCs version 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3, 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, 3.2.1, 3.2.2, 3.3, 3.3.1, 3.3.2, 3.3.3, 3.4 contain an uncontrolled search path vulnerability. A locally authenticated low privileged user could exploit this vulnerability to cause the loading of arbitrary DLLs by the SupportAssist binaries, resulting in the privileged execution of arbitrary code.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Supportassist For Business Pcs | 2.0 |
| Dell | Supportassist For Business Pcs | 2.0.1 |
| Dell | Supportassist For Business Pcs | 2.0.2 |
| Dell | Supportassist For Business Pcs | 2.1 |
| Dell | Supportassist For Business Pcs | 2.1.1 |
| Dell | Supportassist For Business Pcs | 2.1.2 |
| Dell | Supportassist For Business Pcs | 2.1.3 |
| Dell | Supportassist For Home Pcs | 2.0 |
| Dell | Supportassist For Home Pcs | 2.0.1 |
| Dell | Supportassist For Home Pcs | 2.0.2 |
| Dell | Supportassist For Home Pcs | 2.1 |
| Dell | Supportassist For Home Pcs | 2.1.1 |
| Dell | Supportassist For Home Pcs | 2.1.2 |
| Dell | Supportassist For Home Pcs | 2.1.3 |
| Dell | Supportassist For Home Pcs | 2.2 |
| Dell | Supportassist For Home Pcs | 2.2.1 |
| Dell | Supportassist For Home Pcs | 2.2.2 |
| Dell | Supportassist For Home Pcs | 2.2.3 |
| Dell | Supportassist For Home Pcs | 3.0 |
| Dell | Supportassist For Home Pcs | 3.0.1 |
| Dell | Supportassist For Home Pcs | 3.0.2 |
| Dell | Supportassist For Home Pcs | 3.1 |
| Dell | Supportassist For Home Pcs | 3.2 |
| Dell | Supportassist For Home Pcs | 3.2.1 |
| Dell | Supportassist For Home Pcs | 3.2.2 |
| Dell | Supportassist For Home Pcs | 3.3 |
| Dell | Supportassist For Home Pcs | 3.3.1 |
| Dell | Supportassist For Home Pcs | 3.3.2 |
| Dell | Supportassist For Home Pcs | 3.3.3 |
| Dell | Supportassist For Home Pcs | 3.4 |
References
- http://www.dell.com/support/article/SLN320101Patch, Vendor Advisory
- http://www.dell.com/support/article/SLN320101Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-5316?
How severe is CVE-2020-5316?
How do I fix CVE-2020-5316?
Are you affected by CVE-2020-5316?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
