CVE-2021-21518

Description

Dell SupportAssist Client for Consumer PCs versions 3.7.x, 3.6.x, 3.4.x, 3.3.x, Dell SupportAssist Client for Business PCs versions 2.0.x, 2.1.x, 2.2.x, and Dell SupportAssist Client ProManage 1.x contain a DLL injection vulnerability in the Costura Fody plugin. A local user with low privileges could potentially exploit this vulnerability, leading to the execution of arbitrary executable on the operating system with SYSTEM privileges.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.037

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2020-5316,CVE-2021-21518 are affected in Dell SupportAssist 3.3.3Windows
Vulnerabilities CVE-2021-21518 are affected in Dell SupportAssist 3.4.0Windows
Vulnerabilities CVE-2021-21518 are affected in Dell SupportAssist 3.6.0Windows
Vulnerabilities CVE-2021-21518 are affected in Dell SupportAssist 3.7.0Windows
Vulnerabilities CVE-2021-21518,CVE-2023-39249 are affected in Dell SupportAssist 3.4.0Windows
Uncontrolled Search Path Element Vulnerability (CVE-2021-21518)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234