
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-21518 is a DLL injection vulnerability discovered in Dell SupportAssist for Home PCs (versions 3.7.x, 3.6.x, 3.4.x, 3.3.x) and Dell SupportAssist for Business PCs (versions 2.0.x, 2.1.x, 2.2.x). The vulnerability exists in the Costura Fody plugin provided by PC Doctor (Dell Security Advisory).
The vulnerability has a CVSS Base Score of 7.8 with vector string CVSSv3.1: (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The vulnerability allows for DLL injection through the PC Doctor's Costura Fody plugin component (Dell Security Advisory).
A successful exploitation of this vulnerability could allow a local user with low privileges to execute arbitrary executables on the operating system with SYSTEM privileges, potentially leading to complete system compromise (Dell Security Advisory).
The vulnerability requires local access and low privileges to exploit. The attack complexity is rated as low, requiring no user interaction to execute (Dell Security Advisory).
Dell has released updated versions to address this vulnerability: Dell SupportAssist for Home PCs version 3.8.0 and Dell SupportAssist for Business PCs version 2.3.0. Users can update either through automatic updates if enabled, or manually through the SupportAssist application settings (Dell Security Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."