Home
MEDIUM: 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:HDefault status
unaffected
Any version before 4.10.1
affected
Default status
unaffected
Any version before 4.9.0
affected
Description
SupportAssist for Home PCs versions 4.8.2 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain an UNIX Symbolic Link (Symlink) following vulnerability. A low privileged attacker with local access to the system could potentially exploit this vulnerability to delete arbitrary files only in that affected system.
Problem types
CWE-61: UNIX Symbolic Link (Symlink) Following
Product status
Any version before 4.10.1
Any version before 4.9.0
Credits
Dell would like to thank Carson Chan for reporting this issue.
References
www.dell.com/...pportassist-for-business-pcs-vulnerabilities