SecPod

Learn Search

Search across all Learn content

← Back to Expressions & POVs
Dell SupportAssist Assists Attackers

Dell SupportAssist Assists Attackers

Jun 23, 2019By Vidita V Koushik3 min read

Privilege Escalation Vulnerabilities are a dime a dozen these days. But what if an attacker could take control of an application that runs with the highest privileges? Then it’s an apocalypse! A flaw (Dell Support Assist Vulnerability) in an application running with administrator privileges has left millions of Dell PCs vulnerable. A Vulnerability Management System can resolve these issues.

What is Dell SupportAssist?

Dell SupportAssist is software that comes preinstalled on all PCs and installation is manual. According to Dell, this software is in use to ease out the troubleshooting process on Dell devices. SupportAssist is present only for Dell devices running the Windows operating system. SupportAssist can access highly sensitive information present on the hardware. The components of SupportAssist, which can access this data, is by PC Doctor. 

This software is given SYSTEM-level privileges for identifying and resolving hardware and software issues. SupportAssist would be an attractive target for an attacker, given that it is identified as a “signed” service by Microsoft. SafeBreach discovered a vulnerability in this application. These Vulnerabilities can be prevented by using a good vulnerability management tool.

Why is Dell SupportAssist vulnerable?

SupportAssist fails to handle DLLs securely.

SafeBreach observed that when the “Dell Hardware Support” service was started, it initially executes DSAPI.exe(Dell Hardware Support), which executes pcdrwi.exe (PC-Doctor Communications Manager). Next on the list is the execution of a bunch of PC-Doctor executables with “p5x” extension. These collect OS and hardware information for troubleshooting. The actual flaw lies here. The devil is in the details.

When this process is observing using ProcessMonitor, the PE files with the “p5x” extension were loading DLL files to collect information from various resources. Three executables were trying to load files with the names LenovoInfo.dll, AlienFX.dll, atiadlxx.dll, and atiadlxy.dll. A malicious DLL can be in place on a machine and renamed with LenovoInfo.dll, AlienFX.dll, atiadlxx.dll, or atiadlxy.dll. It is perturbing to find out that the application still loads these malicious files and successfully executes them with SYSTEM privileges.

The p5x modules use a utility library named Common.dll. Analysis of this library reveals two factors that contribute to this vulnerability:

  • Improper validationof the DLL to check whether it has a sign or not.
  • Usage of the LoadLibraryW function to load modules which allows an unauthorized user to change the search order and look for DLL files only in the specified folder and not in the PATH variable.

Dell has released a fix for this vulnerability and it is CVE-2019-12280. The updates are automatically installing on PCs if automatic updates are accessible. They can also download and install manually.

Affected Products by Dell Support Assist Vulnerability:

The PC Doctor component in :

  • Dell SupportAssist for Business PCs version 2.0
  • Dell SupportAssist for Home PCs version 3.2.1 and before

Other affected products include PC-Doctor Toolbox for Windows, rebranded as CORSAIR ONE Diagnostics, CORSAIR Diagnostics, Staples EasyTech Diagnostics, Tobii I-Series Diagnostic Tool and Tobii Dynavox Diagnostic Tool.

Impact

An attacker can exploit the DLL-Injection vulnerability in SupportAssist to conduct Application Whitelisting Bypass, Signature Validation Bypass, read sensitive data, or compromise the system.

Solution:

Dell has released a patch to fix this vulnerability. Upgrade to :

  • Dell SupportAssist for Business PCs version 2.0.1
  • Dell SupportAssist for Home PCs version 3.2.2

Therefore, please refer to this KB Article.

Featured Posts

Open Everything You Need to Know About AI-Assisted Cyberattacks and How to Stop Them
Everything You Need to Know About AI-Assisted Cyberattacks and How to Stop Them

Point of View

Everything You Need to Know About AI-Assisted Cyberattacks and How to Stop Them

AI has removed the skill barrier that used to keep amateurs out of serious cybercrime, letting first-time attackers pull off major breaches using chatbots and agentic AI tools. The blog covers the main attack types (AI phishing, deepfakes, AI-generated malware, agentic extortion) with 2025-2026 data, and argues that defense now depends on patching by actual exposure, not static severity scores, across both endpoints and cloud.

Aug 18, 2026

Open Key Considerations While Choosing a CNAPP Platform for Enterprise Cloud Security
Key Considerations While Choosing a CNAPP Platform for Enterprise Cloud Security

Point of View

Key Considerations While Choosing a CNAPP Platform for Enterprise Cloud Security

Aug 17, 2026

Open Top AI Cybersecurity Vendors in 2026
Top AI Cybersecurity Vendors in 2026

Point of View

Top AI Cybersecurity Vendors in 2026

Aug 17, 2026

Open Cybersecurity AI Automation in 2026 and What It Changes in the SOC
Cybersecurity AI Automation in 2026 and What It Changes in the SOC

Point of View

Cybersecurity AI Automation in 2026 and What It Changes in the SOC

Aug 17, 2026