CVE-2023-39249

CVSS V2 None CVSS V3 None
Description
Dell SupportAssist for Business PCs version 3.4.0 contains a local Authentication Bypass vulnerability that allows locally authenticated non-admin users to gain temporary privilege within the SupportAssist User Interface on their respective PC. The Run as Admin temporary privilege feature enables IT/System Administrators to perform driver scans and Dell-recommended driver installations without requiring them to log out of the local non-admin user session. However, the granted privilege is limited solely to the SupportAssist User Interface and automatically expires after 15 minutes.
Overview
  • CVE ID
  • CVE-2023-39249
  • Assigner
  • dell
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-02-14T07:36:06.873Z
  • Last Modified Date
  • 2024-02-14T07:36:06.873Z
History
Created Old Value New Value Data Type Notes
2024-06-25 19:19:46 Added to TrackCVE