Dell SupportAssist Software Vulnerability Exposed by 17-Year Old Security Researcher: Report

If you’ve purchased a Dell laptop recently, you might want to update this software immediately.

Advertisement
By Roydon Cerejo | Updated: 6 May 2019 15:33 IST
Highlights
  • The vulnerability affects SupportAssist program on Dell laptops
  • The flaw could allow potential hackers to install malware on your laptop
  • Dell has released an update to fix this issue

Dell's SoftwareAssist app has recently been patched to fix this vulnerability

Most laptops we purchase come with a tonne of pre-installed apps from the manufacturers. A lot of these are generally things you'll never use but some of them can be useful, like Dell's SupportAssist program, which automatically scans your laptop for updates and installs them. However, recently a major vulnerability has been discovered in this software, which leaves your laptop open to attack from hackers. This issue affects most recent Dell laptops that have SupportAssist client version prior to 3.2.0.90. Dell has now acknowledged the issue and has released an update to fix it.

The issue was discovered by a 17-year old security researcher named Bill Demirkapi, who has chronicled his findings in his blog post. According to the post, Demirkapi stumbled upon this when he purchased a Dell G3 15 gaming laptop. He upgraded the bundled hard drive to an SSD, after which he had to re-install Windows and other utilities from Dell. Dell's SupportAssist program intrigued him since the program is designed to automatically check for system and driver updates, which means it has administrator access to modify critical parts of the operating system.

The way in which this can be exploited, as Demirkapi explains, is when the SupportAssist software makes a request to Dell's website, in order to check for new drivers, a hacker could intercept the request and re-direct it to a rogue website, thereby installing malicious code on your machine, instead of the legitimate update. For this to work, the hacker needs to be on the same network as you so while this might not affect people on private networks, it can be an issue when you use public Wi-Fi networks such as airports or a coffee shop. Demirkapi has posted a step-by-step guide, along with source code on his blog, of how an attacker might take advantage of this flaw.

Advertisement

Demirkapi found this vulnerability back in October 2018 and reached out to Dell for the same. Dell later confirmed the vulnerability and finally released a fix for the same last month. If you're using SupportAssist on your Dell laptop and the version is below 3.2.0.90, download the latest version from Dell website immediately to safeguard your computer.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Dell, SupportAssist, hacking
Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 15R With 7,400mAh Battery, Snapdragon 8 Gen 5 Debuts at This Price
  2. Apple's iPhone 18 Pro, iPhone Fold May Feature a Relocated Selfie Camera
  3. OnePlus Pad Go 2 Launched in India With 10,050mAh Battery, 5G Connectivity
  4. Realme 16 Pro+ 5G Listed on Certification Website With These Specifications
  5. Dhurandhar OTT Release Date: What We Know So Far
  6. OnePlus 15R, OnePlus 15R Ace Edition Launch Today: All You Need to Know
  7. Motorola Signature Phone Could Launch Soon: See Leaked Design, Colourways
  8. Vivo V70 Stops By US FCC Database Along With RAM and Storage Details
  9. OnePlus 15, Nord CE 5 Prices Slashed During Community Sale: See Offers
  10. Google Labs' New AI Agent Will Help You Better Organise Your Day
  1. Interstellar Comet 3I/ATLAS Nears Earth on Dec. 19, Offering Rare Insights Into Cosmic Visitors
  2. Europe’s Ariane 6 Rocket Lifts Off With First Galileo Satellites, Boosting Europe’s Navigation Network
  3. NASA’s Parker Solar Probe Observes Solar Wind Making ‘U-Turn’, Shedding Light on Space Weather
  4. ESA Reveals City-Size ‘Cosmic Butterfly’ Crater on Mars Containing Signs of Ancient Water
  5. The Holy Grail of Eris OTT Release: Know When and Where to Watch it Online
  6. OnePlus Pad Go 2 Launched in India With 10,050mAh Battery, 12.1-Inch Display and 5G Connectivity: Price, Features
  7. OnePlus 15R Launched in India With 7,400mAh Battery, Snapdragon 8 Gen 5 SoC: Price, Specifications
  8. Flex By Google Pay: Google Partners With Axis Bank to Introduce UPI-Powered, Digital Credit Card
  9. Warner Bros. Plans to Reject Paramount Bid on Funding, Terms
  10. Amazon Pay Adds Support for Biometric Authentication for UPI Payments in India
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.