Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Vulnerabilities found in Dell BIOSConnect features within Dell SupportAssist
https://techxplore.com ^ | June 28, 2021 | by Bob Yirka

Posted on 06/28/2021 11:47:59 AM PDT by Red Badger

A team of engineers at computer security company Eclypsium, Inc. has found four vulnerabilities in Dell BIOSConnect features within Dell SupportAssist. They have reported what they found on their website where they have rated the vulnerability as High.

Dell Computer Technology Company is one of the largest makers of personal computers in the world. As part of their efforts to support their customers the company began installing a BIOS-based application called SupportAssist, which, as its name suggests, is meant to allow Dell technicians to assist users remotely. Dell also preinstalls another BIOS app called BIOS Connect on the computers it sells, which allows the company to update the BIOS of the computers its sells. In this new effort, the team at Eclypsium found a security chain vulnerability that could allow what they describe as 'adversaries' to gain access to the boot process of user computers, which could be used to load adversarial software.

Eclypsium reported the problems it found to Dell this past March, and Dell promptly issued a security advisory to its customers and set about working up a fix. Two of the fixes were completed and updated on server-side machines—the other two, once completed, were sent to Dell's cloud site. Those fixes are now available for those customers who have been impacted; those who have Dell auto-updates turned on need not worry as the updates for they have likely taken place already.

The vulnerability involved 129 different Dell devices, from laptops, to desktops and tablet devices and likely impacted approximately 30 million computers around the world. One of the vulnerabilities involved connections between BIOS updates and Dell servers that could allow an adversary to redirect a computer being updated to an adversarial machine. The other three vulnerabilities were listed as overflow vulnerabilities.

Eclypsium's engineers noted on their website that any attack meant to take advantage of the vulnerability would have had to involve redirecting user computers, which made the likelihood of an attack on individual users very remote. Any such attacks would have been far more likely to take aim at large enterprises with a lot of payoff for adversaries.

Explore further

As more work from home, Dell unveils new BIOS shield More information: Dell: www.dell.com/support/kbdoc/nl- … d-https-boot-feature


TOPICS: Business/Economy; Computers/Internet; History; Society
KEYWORDS:
Navigation: use the links below to view more comments.
first 1-2021-27 next last

1 posted on 06/28/2021 11:47:59 AM PDT by Red Badger
[ Post Reply | Private Reply | View Replies]

To: dayglored; ShadowAce; Swordmaker

Techy Pingy!.....................


2 posted on 06/28/2021 11:48:32 AM PDT by Red Badger (Homeless veterans camp in the streets while illegal aliens are put up in hotels.....................)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger

As much as I hate it it’s back to Apple sooner rather than later.


3 posted on 06/28/2021 11:50:35 AM PDT by ImJustAnotherOkie (All I know is The I read in the papers.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ImJustAnotherOkie

I might go Apple for the next box.

Not sure.


4 posted on 06/28/2021 11:57:55 AM PDT by wally_bert (I cannot be sure for certain, but in my personal opinion I am certain that I am not sure.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Red Badger

And should I wait to buy a new laptop and what’s the best brand out there besides: HP, DELL, and Apple?


5 posted on 06/28/2021 11:58:25 AM PDT by SkyDancer (I Identify As Vaccinated)
[ Post Reply | Private Reply | To 1 | View Replies]

To: All

That’s a Feature, not a bug.

Dell’s suck anyway. They are designed to fail, designed to be irreparable. At least their laptops.


6 posted on 06/28/2021 11:59:24 AM PDT by LegendHasIt
[ Post Reply | Private Reply | To 1 | View Replies]

To: SkyDancer

I’ve had a couple of Toshiba laptops that were / are good, and a Sony Vaio laptop that is 20 years old and still works fine... I don’t know if Sony still even makes computers though.


7 posted on 06/28/2021 12:03:53 PM PDT by LegendHasIt
[ Post Reply | Private Reply | To 5 | View Replies]

To: Red Badger

“Hey let’s put in a BIOS hook that let’s us access the user’s computer remotely with total admin/root permissions. What could possibly go wrong?”


8 posted on 06/28/2021 12:06:13 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 2 | View Replies]

To: dayglored
"let's" -> lets

Feh, I hate it when I do that.

9 posted on 06/28/2021 12:07:02 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 8 | View Replies]

To: Red Badger

Uninstall Dell SupportAssist. Take it upon yourself to check for BIOS and driver updates rather than let Dell do it “automatically”. One less application running in the background.


10 posted on 06/28/2021 12:08:54 PM PDT by CatOwner (Don't expect anyone, even conservatives, to have your back when the SHTF in 2021)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger

That reminds me to check my Lenovo, got a BIOS update; yeah! Updated.


11 posted on 06/28/2021 12:09:14 PM PDT by \/\/ayne (I regret that I have but one subscription cancellation notice to give to my local newspaper)
[ Post Reply | Private Reply | To 1 | View Replies]

To: LegendHasIt

What about Asus?


12 posted on 06/28/2021 12:09:47 PM PDT by SkyDancer (I Identify As Vaccinated)
[ Post Reply | Private Reply | To 7 | View Replies]

To: \/\/ayne

Courtesy of Chairman Xi!.....................


13 posted on 06/28/2021 12:09:58 PM PDT by Red Badger (Homeless veterans camp in the streets while illegal aliens are put up in hotels.....................)
[ Post Reply | Private Reply | To 11 | View Replies]

To: wally_bert

That 13 pro would work for for now.


14 posted on 06/28/2021 12:13:20 PM PDT by ImJustAnotherOkie (All I know is The I read in the papers.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: SkyDancer

I’ve only had one ASUS, about 10 years ago. It lasted about 4-6 months of light use. I forgot what went wrong with it, but it was fatal.


15 posted on 06/28/2021 12:14:40 PM PDT by LegendHasIt
[ Post Reply | Private Reply | To 12 | View Replies]

To: SkyDancer

What do you use the laptop for? That would determine which direction you should go.


16 posted on 06/28/2021 12:24:57 PM PDT by LesbianThespianGymnasticMidget
[ Post Reply | Private Reply | To 5 | View Replies]

To: ImJustAnotherOkie

I bought my last PC tower as of a few years ago.

A great Dell unit and zero trouble from a hardware standpoint.

I have a few more legacy ones that have been Linux boxes at times with flat panel monitors that collect dust. One is was a custom built development server.

I’ve also been hauling off bins of burned discs that have never been looked at, labeled, or touched since they were made. Most are decades old. What ones I have checked have little of importance. Crush them.


17 posted on 06/28/2021 12:25:30 PM PDT by wally_bert (I cannot be sure for certain, but in my personal opinion I am certain that I am not sure.)
[ Post Reply | Private Reply | To 14 | View Replies]

To: LesbianThespianGymnasticMidget

Oh, emails of course, surfing the web; no game playing though. Might want Word on it as well.


18 posted on 06/28/2021 12:31:12 PM PDT by SkyDancer (I Identify As Vaccinated)
[ Post Reply | Private Reply | To 16 | View Replies]

To: Red Badger

Was it on the Dominion voting machines?


19 posted on 06/28/2021 12:38:56 PM PDT by Renkluaf
[ Post Reply | Private Reply | To 1 | View Replies]

To: LegendHasIt
I’ve had a couple of Toshiba laptops that were / are good, and a Sony Vaio laptop that is 20 years old and still works fine.

Toshiba went WAY down hill in their laptops over the last 20 years. They used to be the cream of the crop, but that was largely when companies like NEC and Zenith were big players in the laptop market. Sony stopped competing there a while ago.
20 posted on 06/28/2021 12:57:27 PM PDT by Dr. Sivana (“At first you go bankrupt slowly, then all at once.” -- Hemingway)
[ Post Reply | Private Reply | To 7 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-27 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson