Authentication bypass using an alternate path or channel in SupportAssist for Business PCs - CVE-2023-39249
Published: August 17, 2023
SupportAssist for Business PCs
Dell
Description
The vulnerability allows a local user to bypass security restrictions.
The vulnerability exists due to Run as Admin temporary privilege feature enables IT/System Administrators to perform driver scans and Dell-recommended driver installations without requiring them to log out of the local non-admin user session. A local user can gain temporary privilege within the SupportAssist User Interface on their respective PC.