Later archive addition
Remote Code Execution on most Dell computers
The article chains Dell SupportAssist’s privileged localhost web API, reusable command signatures, weak Dell-origin checks, DNS interception, and a URL-normalization bypass into remote code execution. A malicious page can make the agent download an attacker-substituted executable from an allowlisted HTTP hostname and run it as Administrator.
Record
- Researcher
- @BillDemirkapi and Bill Demirkapi
- Published by
- Bill Demirkapi's Blog
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of @BillDemirkapi and Bill Demirkapi, first published at the original source. Preserved copies are kept so the citation survives its host.