Dell Says Millions of PCs at Risk Due to Critical Flaw in SupportAssist Tool; Fix Issued

Dell has already released a patch for the vulnerability.

Advertisement
By Tasneem Akolawala | Updated: 21 June 2019 18:41 IST
Highlights
  • The problem lies in the PC-Doctor component of SupportAssist app
  • Dell has issued an update for SupportAssist tool with the fix
  • Users are advised to update the tool immediately

Dell PCs are at risk of remote attack due to newly discovered bug

A new vulnerability has been discovered in Dell computers that have left millions of systems at risk of a privilege-escalation attack. Dell has released a security advisory warning for all of its consumers to update their laptops and PCs to patch the said vulnerability. The flaw was once agani found in the SupportAssist tool that is bundled with every Dell computer, and this vulnerability was first spotted by SafeBreach. The CVE-2019-12280 vulnerability exists in SupportAssist app for business v2.0 and home PCs v 3.2.1 and prior.

As mentioned, SafeBreach was the one that discovered the flaw and reported this vulnerability. It allows hackers to take over the machine and read the physical memory stored onboard. The problem lies in the SupportAssist tool that is bundled with nearly every Dell computer. The vulnerability lies in the PC-Doctor component. SafeBreach warns that it is possible to "exploit this vulnerability in order to load an arbitrary unsigned DLL into a service that runs as SYSTEM, achieving privilege escalation and persistence". The firm notes that there could well be over 100 million Dell systems that may be affected. Notably, this is the second major vulnerability in the SupportAssist tool found in 2019, with another reported in March.

Advertisement

Dell has already issued an update and "recommends all customers to update at the earliest opportunity." If auto-update is enabled, then the company should have already updated SupportAssist for Business PCs and SupportAssist for Home PCs automatically. However, a whole step-by-step guide can also be found on its security advisory page.

The company further told Tom's Guide, “Dell SupportAssist is not made by PC-Doctor. The vulnerability discovered by SafeBreach is a PC-Doctor vulnerability, which is a third-party component that ships with Dell SupportAssist for PCs. More than 90 percent of customers to date have received the update, released on May 28, 2019, and are no longer at risk. Dell SupportAssist updates automatically if automatic updates are enabled, and most customers have automatic updates turned on.”

Advertisement

All Dell PC and laptop users are advised to check if they are updated to the latest version of SupportAssist. You need to be on Dell SupportAssist for Business PCs version 2.0.1 or Dell SupportAssist for Home PCs version 3.2.2 to ensure that you are safe from any unwanted attacks.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Dell, SupportAssist, SafeeBreach
Advertisement

Related Stories

Popular Mobile Brands
  1. Poco X8 Series Arrives in India With 50-Megapixel Camera: See Price
  2. Oppo K14 5G Debuts With 7,000mAh Battery at This Price in India
  3. Realme P4 Lite 5G Roundup: Price in India, Specifications Expected
  4. Vivo T5x 5G Goes Official in India With 7,200mAh Battery
  5. Here's How Much the Poco X8 Pro Series Could Cost in India
  6. Samsung Could Equip Galaxy Z Fold 8, Wide Fold With These Batteries
  7. iQOO 15R Review
  8. Best Mobiles Under Rs. 25,000 in India
  9. Apple Launches AirPods Max 2 With New H2 Chip, Improved ANC: See Details
  10. Oura Ring 4 Launched as Company's First Smart Ring in India at This Price
  1. Oppo Find N6 Launched With Snapdragon 8 Elite Gen 5 SoC, 6,000mAh Battery: Price, Features
  2. Poco X8 Pro Series Launched in India With Up to 9,000mAh Battery, 50-Megapixel Camera: Price, Specifications
  3. OnePlus Pad 3 Tipped to Launch With 13.2-Inch Display, Snapdragon 8 Elite Gen 5 Chip
  4. Vivo X500 Series Chipsets Tipped Months Ahead of Launch; Vivo Pro Max Could Also Debut
  5. Oura Ring 4 Launched in India With Smart Sensing Technology and HRV Tracking: Price, Specifications
  6. Sony's Upgraded PSSR Upscaler Is Rolling Out to Silent Hill f, Crimson Desert and More Games on PS5 Pro
  7. Google, Amazon, Microsoft and Others Join Hands to Fight Online Scams and Fraud
  8. Oppo K14 5G Launched in India With 7,000mAh Battery, 50-Megapixel Camera: Price, Specifications
  9. Operation Atlantic: Canada, UK and US Conduct Joint Operation to Disrupt Crypto Fraud Networks
  10. Samsung Galaxy Z TriFold Sales Set to End Just Three Months After Launch: Report
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.