时间:2025-11-22 10:57:31 来源:网络整理编辑:綜合
If you own a Dell laptop or desktop then there's a very good chance your machine is vulnerable to at
If you own a Dell laptop or desktop then there's a very good chance your machine is vulnerable to attack simply by visiting a malicious website. The good news is, Dell has released a patch to close the security hole.
As ZDNet reports, 17-year-old security researcher Bill Demirkapi discovered a vulnerability (CVE-2019-3719) in the Dell SupportAssist utility which allows an attacker to remote execute code. This is achieved by getting a user to visit a specific website containing JavaScript code capable of tricking the SupportAssist app into downloading and running malicious files (with full admin rights). Importantly, no user interaction is required once the website has been visited and the JavaScript can be hidden inside an ad on a legitimate website.
Here's the remote code execution in action as recorded by Demirkapi:
Dell uses SupportAssist to pro-actively check the health of your hardware and software and then automatically updates each system as necessary. As you've probably guessed, it's a piece of software that gets pre-installed on most new Dell systems, meaning there's a lot of users out there potentially vulnerable to this attack.

Dell has known about the vulnerability since Oct. 26 last year and a patched version of SupportAssist (v3.2.0.90) is now available which closes the security hole. If you own a Dell which has SupportAssist installed, download and install the new version as soon as possible to protect your system.
TopicsCybersecurityDell
There's a big piece of fake chicken stuck to this phone case2025-11-22 10:42
Google bought more renewable energy than it needed last year2025-11-22 10:39
These 'New Yorker' cartoons get a creative twist with Kanye's tweets2025-11-22 10:27
Spyro the dragon returns in 'Spyro Reignited Trilogy'2025-11-22 10:15
WhatsApp announces plans to share user data with Facebook2025-11-22 09:29
Highly resourceful woman has the wildest birth story of all time2025-11-22 09:24
'Bachelor in Paradise' is under fire for queerbaiting viewers2025-11-22 09:15
'God of War' is the game I've been waiting for my whole life2025-11-22 09:10
J.K. Rowling makes 'Harry Potter' joke about Olympics event2025-11-22 08:54
Restaurant makes cute pun cake for a recovering diner2025-11-22 08:52
More than half of women in advertising have faced sexual harassment, report says2025-11-22 10:30
5 questions Mark Zuckerberg should answer in front of Congress2025-11-22 10:26
Here's how to upgrade to Google's new Gmail right now2025-11-22 10:21
Twitter thinks it's solved the case of who threatened Stormy Daniels2025-11-22 10:18
Felix the cat just raised £5000 for charity because she's the hero we all need2025-11-22 09:37
'Shadow of the Tomb Raider' preview2025-11-22 09:18
Data scientist behind Cambridge Analytica scandal apologises2025-11-22 09:06
HTC Vive Pro review: The best VR headset2025-11-22 08:53
Make money or go to Stanford? Katie Ledecky is left with an unfair choice.2025-11-22 08:44
7 ways to transform your Netflix account into a movie lover’s dream2025-11-22 08:28