SupportAssist Client version 3.8 and 3.9 contains an Untrusted search path vulnerability that allows attackers to load an arbitrary .dll file via .dll planting/hijacking, only by a separate administrative action that is not a default part of the SOSInstallerTool.exe installation for executing arbitrary dll's,
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: dell
Published: 2021-09-28T19:20:28.930601Z
Updated: 2024-09-16T20:38:07.749Z
Reserved: 2021-07-08T00:00:00
Link: CVE-2021-36297
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-09-28T20:15:07.780
Modified: 2024-11-21T06:13:26.890
Link: CVE-2021-36297
Redhat
No data.