CVE-2019-3719
HIGH 8.0EPSS 16.1%
Dell SupportAssist Client versions prior to 3.2.0.90 contain a remote code execution vulnerability. An unauthenticated attacker, sharing the network access layer with the vulnerable system, can compromise the vulnerable system by tricking a victim user into downloading and executing arbitrary executables via SupportAssist client from attacker hosted sites.
- CVSS v3.1
- 8.0 HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v3.0
- 7.1 HIGH
CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.9 HIGH
AV:A/AC:M/Au:N/C:C/I:C/A:C - EPSS
- 16.14% chance of exploitation in the next 30 days, 97th percentile
- Published
- 2019-04-18
- Updated
- 2024-09-16
Proof-of-concept exploits (2)
- D4stiny/Dell-Support-Assist-RCE-PoC163★ · 2019-05-01
- jiansiting/CVE-2019-37194★ · 2019-05-01