CVE-2021-21518

HIGH

Dell Supportassist Client Promanage - Uncontrolled Search Path

Title source: rule

Description

Dell SupportAssist Client for Consumer PCs versions 3.7.x, 3.6.x, 3.4.x, 3.3.x, Dell SupportAssist Client for Business PCs versions 2.0.x, 2.1.x, 2.2.x, and Dell SupportAssist Client ProManage 1.x contain a DLL injection vulnerability in the Costura Fody plugin. A local user with low privileges could potentially exploit this vulnerability, leading to the execution of arbitrary executable on the operating system with SYSTEM privileges.

Scores

CVSS v3 7.8
EPSS 0.0004
EPSS Percentile 10.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427
Status published

Affected Products (8)

dell/supportassist_client_promanage
dell/supportassist_for_business_pcs
dell/supportassist_for_business_pcs
dell/supportassist_for_business_pcs
dell/supportassist_for_home_pcs
dell/supportassist_for_home_pcs
dell/supportassist_for_home_pcs
dell/supportassist_for_home_pcs

Timeline

Published Mar 12, 2021
Tracked Since Feb 18, 2026