If you own a Dell laptop or desktop then there's a very good chance your machine is vulnerable to attack simply by visiting a malicious website. The good news is, Dell has released a patch to close the security hole.
As ZDNet reports, 17-year-old security researcher Bill Demirkapi discovered a vulnerability (CVE-2019-3719) in the Dell SupportAssist utility which allows an attacker to remote execute code. This is achieved by getting a user to visit a specific website containing JavaScript code capable of tricking the SupportAssist app into downloading and running malicious files (with full admin rights). Importantly, no user interaction is required once the website has been visited and the JavaScript can be hidden inside an ad on a legitimate website.
Here's the remote code execution in action as recorded by Demirkapi:
Dell uses SupportAssist to pro-actively check the health of your hardware and software and then automatically updates each system as necessary. As you've probably guessed, it's a piece of software that gets pre-installed on most new Dell systems, meaning there's a lot of users out there potentially vulnerable to this attack.
Dell has known about the vulnerability since Oct. 26 last year and a patched version of SupportAssist (v3.2.0.90) is now available which closes the security hole. If you own a Dell which has SupportAssist installed, download and install the new version as soon as possible to protect your system.
Copyright © 2023 Powered by
Dell laptops and desktops vulnerable to remote attack-寸地尺天网
sitemap
文章
2
浏览
7
获赞
21852
These new photos of Prince Louis will make you swoon at his cuteness
There's one relatively new royal family tradition that I can definitely get behind. That's the birthApple’s $6,000 Mac Pro has $400 wheels
Look, we get it. Sometimes you want your nachos on the go. But when it comes to Apple's new $6,000 cJaime Harrison brought a plexiglass divider to debate Lindsey Graham
If there's one word that can perfectly describe Jaime Harrison in his first debate against Sen. LindIt's finally time to unfollow the Trumps on every platform
After what feels like 425 tearful, anxiety-ridden, brain worms-filled decades (but has somehow onlyArtists on Twitter are drawing their favorite shipping dynamics for this new meme
Once you've binge-watched enough Netflixshows, you start to see a pattern in the characters you getThe 40 best horror movies that center women's stories
Women and horror movies make for strange bedfellows — yet also simultaneously one of the mostThe Analog Embrace: How Some Experiences Are Surviving the Digital Age
Zeroes and ones were promised to be the future, with digital media taking over in several ways. ButTikTok's first user to hit 100 million followers is Charli D'Amelio
Charli D'Amelio's meteoric rise on TikTok just hit a milestone that no one else has so far: 100 millWe shot Portrait mode video with this iPhone app
Ever take a Portrait mode photo on your iPhone and wish you could do the same with video?Well, you'rAnatomy of a Keyboard
Input devices like keyboards have a key role in the computing and gaming landscape, so the guts of tThe best DevaCurl alternatives and replacements for curly hair
Essentials Week spotlights unexpected items that make our daily lives just a little bit better.AlmosWhy Apple, Google, and other big tech companies create their own fonts
After its famous 1984 Super Bowl commercial, Apple officially unveiled the Macintosh 128k, the "theLenovo Flex 5G laptop now available through Verizon
5G isn't just for phones. Starting this week, you can buy a real, actual laptop that connects to the5 cool CES products you can get your hands on in 2020
The annual Consumer Electronics Show in Las Vegas is always a showcase for things you might not everThe 40 best horror movies that center women's stories
Women and horror movies make for strange bedfellows — yet also simultaneously one of the most