Newsletter Archives
-
Dell patches SupportAssist, but other PC-Doctor software still vulnerable
Dell announced on June 21 that it has issued an emergency patch for the Dell SupportAssist software – which you’re probably running if you have a Dell computer and didn’t wipe out the pre-installed garbage.
Specifically, the PC-Doctor component of SupportAssist has a vulnerability in the way it checks (or, er, doen’t check) the validity of certain DLLs on your computer. If somebody sticks a bad DLL on your machine, in a specific location and with a specific file name, PC-Doctor helpfully picks it up and runs it – with system-level privileges. SafeBreak Labs, which discovered and reported the bug, has a full description.
Dell ain’t the only one. Apparently PC-Doctor Toolbox is also part of
CORSAIR ONE Diagnostics
CORSAIR Diagnostics
Staples EasyTech Diagnostics
Tobii I-Series Diagnostic Tool
Tobii Dynavox Diagnostic ToolYou may recall that Dell SupportAssist had a big security breach back in May, 2019. Beats me why anyone would continue to use crapware like it.