【】

If you own a Dell laptop or desktop then there's a very good chance your machine is vulnerable to attack simply by visiting a malicious website. The good news is, Dell has released a patch to close the security hole.
As ZDNet reports, 17-year-old security researcher Bill Demirkapi discovered a vulnerability (CVE-2019-3719) in the Dell SupportAssist utility which allows an attacker to remote execute code. This is achieved by getting a user to visit a specific website containing JavaScript code capable of tricking the SupportAssist app into downloading and running malicious files (with full admin rights). Importantly, no user interaction is required once the website has been visited and the JavaScript can be hidden inside an ad on a legitimate website.
Here's the remote code execution in action as recorded by Demirkapi:
Dell uses SupportAssist to pro-actively check the health of your hardware and software and then automatically updates each system as necessary. As you've probably guessed, it's a piece of software that gets pre-installed on most new Dell systems, meaning there's a lot of users out there potentially vulnerable to this attack.

Dell has known about the vulnerability since Oct. 26 last year and a patched version of SupportAssist (v3.2.0.90) is now available which closes the security hole. If you own a Dell which has SupportAssist installed, download and install the new version as soon as possible to protect your system.
Featured Video For You
Scientists successfully 3D-print heart from human cells
TopicsCybersecurityDell
相关文章
This company is hiring someone just to drink all day
For the non-Don Drapers among us, drinking at work is a far-off fantasy. But UK company ILoveGin wan2025-09-16Reports of unresponsive Samsung Galaxy phones pile up after big AI update
Samsung Galaxy users are on Reddit and the Samsung Community forum posting complaints about their de2025-09-16- 作為辦公室工作人員,通常一半以上的時間都坐在凳子上,但是長時間坐著不好,會引起背痛和屁股疼痛的問題,更可能會導致屁股疼。這與長時間不活動有很大的關係,還有一個原因就是凳子的材質都是很硬的 ,所以引起疼痛2025-09-16
iPadOS 18: 3 iPads are reportedly not getting Apple's update
Every year, Apple releases a brand new version of its mobile operating systems: iOS for the iPhone a2025-09-16Despite IOC ban, Rio crowds get their political messages across
The Olympics aren't meant to be a place for political expression -- the International Olympic Commit2025-09-16Best monitor deal: A ton of Samsung monitors are up to 45% off at Amazon
SAVE UP TO 45%:As of April 2, several Samsung monitors are on sale at Amazon, with several premium m2025-09-16
最新评论