CVE-2021-21518
HIGHDell Supportassist Client Promanage - Uncontrolled Search Path
Title source: ruleDescription
Dell SupportAssist Client for Consumer PCs versions 3.7.x, 3.6.x, 3.4.x, 3.3.x, Dell SupportAssist Client for Business PCs versions 2.0.x, 2.1.x, 2.2.x, and Dell SupportAssist Client ProManage 1.x contain a DLL injection vulnerability in the Costura Fody plugin. A local user with low privileges could potentially exploit this vulnerability, leading to the execution of arbitrary executable on the operating system with SYSTEM privileges.
Scores
CVSS v3
7.8
EPSS
0.0004
EPSS Percentile
10.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-427
Status
published
Affected Products (8)
dell/supportassist_client_promanage
dell/supportassist_for_business_pcs
dell/supportassist_for_business_pcs
dell/supportassist_for_business_pcs
dell/supportassist_for_home_pcs
dell/supportassist_for_home_pcs
dell/supportassist_for_home_pcs
dell/supportassist_for_home_pcs
Timeline
Published
Mar 12, 2021
Tracked Since
Feb 18, 2026