CVE-2021-36297

HIGH

SupportAssist Client <3.8-3.9 - Code Injection

Title source: llm
STIX 2.1

Description

SupportAssist Client version 3.8 and 3.9 contains an Untrusted search path vulnerability that allows attackers to load an arbitrary .dll file via .dll planting/hijacking, only by a separate administrative action that is not a default part of the SOSInstallerTool.exe installation for executing arbitrary dll's,

Scores

CVSS v3 7.8
EPSS 0.0005
EPSS Percentile 16.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-426
Status published
Products (1)
dell/supportassist_for_home_pcs < 3.9.0
Published Sep 28, 2021
Tracked Since Feb 18, 2026