Vulnerability Description
Dell SupportAssist Client for Consumer PCs versions 3.7.x, 3.6.x, 3.4.x, 3.3.x, Dell SupportAssist Client for Business PCs versions 2.0.x, 2.1.x, 2.2.x, and Dell SupportAssist Client ProManage 1.x contain a DLL injection vulnerability in the Costura Fody plugin. A local user with low privileges could potentially exploit this vulnerability, leading to the execution of arbitrary executable on the operating system with SYSTEM privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Supportassist Client Promanage | 1.0 |
| Dell | Supportassist For Business Pcs | 2.0.0 |
| Dell | Supportassist For Home Pcs | 3.3.3 |
Related Weaknesses (CWE)
References
- https://www.dell.com/support/kbdoc/en-us/000184012/dsa-2021-052-dell-supportassiVendor Advisory
- https://www.dell.com/support/kbdoc/en-us/000184012/dsa-2021-052-dell-supportassiVendor Advisory
FAQ
What is CVE-2021-21518?
CVE-2021-21518 is a vulnerability with a CVSS score of 7.8 (HIGH). Dell SupportAssist Client for Consumer PCs versions 3.7.x, 3.6.x, 3.4.x, 3.3.x, Dell SupportAssist Client for Business PCs versions 2.0.x, 2.1.x, 2.2.x, and Dell SupportAssist Client ProManage 1.x con...
How severe is CVE-2021-21518?
CVE-2021-21518 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-21518?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Supportassist Client Promanage, Dell Supportassist For Business Pcs, Dell Supportassist For Home Pcs.