Dell SupportAssist ¿Í»§¶Ë¶à¸öÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-05-23

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-3718£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.6£¬£¬£¬¹Ù·½£º8.8

CVE±àºÅ£ºCVE-2019-3719£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.1£¬£¬£¬¹Ù·½£º8.0


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾

3.2.0.90 ֮ǰµÄ Dell SupportAssist ¿Í»§¶Ë°æ±¾


Îó²î¸ÅÊö


Dell SupportAssist ¿Í»§¶ËÊÇÃÀ¹ú´÷¶û£¨Dell£©¹«Ë¾µÄÒ»¿î¿Í»§¶ËÓ¦ÓóÌÐò¡£¡£¡£¡£¸Ã³ÌÐòÌṩ×Ô¶¯»¯¡¢×Ô¶¯ºÍÕ¹ÍûÐÔÊÖÒÕ¾ÙÐйÊÕÏɨ³ýµÈ¡£¡£¡£¡£Dell SupportAssist ¿Í»§¶Ë±£´æÒÔÏÂÎó²î£º
CVE-2019-3718
Dell SupportAssist ¿Í»§¶Ë°æ±¾°üÀ¨²»µ±Ô­Ê¼ÑéÖ¤Îó²î¡£¡£¡£¡£Î´ÂÄÀúÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÄÜ»áʹÓôËÎó²îÀ´ÊµÑé¶ÔÊÜÓ°ÏìϵͳµÄÓû§Ìᳫ CSRF ¹¥»÷¡£¡£¡£¡£
CVE-2019-3719

Dell SupportAssist ¿Í»§¶Ë°æ±¾ÖаüÀ¨Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£ÓëÒ×Êܹ¥»÷µÄϵ×ܹ²ÏíÍøÂç»á¼û²ãµÄδÂÄÀúÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýÓÕʹÊܺ¦Óû§Í¨¹ý SupportAssist ¿Í»§¶Ë´Ó¹¥»÷ÕßÍйܵÄÕ¾µãÏÂÔØºÍÖ´ÐÐí§Òâ¿ÉÖ´ÐÐÎļþ£¬£¬£¬´Ó¶øÈëÇÖÒ×Êܹ¥»÷µÄϵͳ¡£¡£¡£¡£


Îó²îÑéÖ¤

CVE-2019-3719 POC£ºhttps://github.com/D4stiny/Dell-Support-Assist-RCE-PoC¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Ð°汾ÒÔÐÞ¸´Îó²î£¬£¬£¬ÇëÓû§Éý¼¶ÖÁDell SupportAssist ¿Í»§¶Ë°æ±¾ 3.2.0.90 ºÍ¸ü¸ß°æ±¾£ºhttps://downloads.dell.com/serviceability/Catalog/SupportAssistInstaller.exe¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.dell.com/support/article/cn/zh/cndhs1/sln316857/dsa-2019-051-dell-supportassist-client-multiple-vulnerabilities?lang=en