CVE-2019-12280
Description
An uncontrolled search path in PC-Doctor Toolbox before 7.3 allows DLL hijacking by an admin who modifies the PATH environment variable.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An uncontrolled search path in PC-Doctor Toolbox before 7.3 allows DLL hijacking by an admin who modifies the PATH environment variable.
Vulnerability
PC-Doctor Toolbox for Windows before version 7.3 contains an uncontrolled search path element that can lead to DLL hijacking [1]. The vulnerability affects the PC-Doctor Toolbox for Windows and also the Dell Hardware Support Service within Dell SupportAssist, as well as rebranded versions for other OEMs [1]. The issue arises when the system's PATH environment variable includes a folder writable by non-admin users and a malicious DLL is crafted to exploit PC-Doctor's administrative privileges [1].
Exploitation
To exploit this vulnerability, an attacker must first have administrative access to modify the system's PATH environment variable to include a folder writable by non-admin users [1]. Then the attacker places a crafted DLL in that folder, which PC-Doctor's service will load due to the altered search order, escalating privileges through the service's administrative rights [1]. The default Windows configuration does not allow this; the vulnerability is only reachable after a non-default change to the PATH [1].
Impact
Successful exploitation allows an attacker with initial administrative access to achieve privilege escalation [1]. The attacker can execute arbitrary code with the elevated privileges of the PC-Doctor service, which runs with administrative rights [1]. This could lead to full system compromise, including data disclosure, modification, or disruption of system functionality.
Mitigation
PC-Doctor released updates to affected customers between May 28, 2019, and June 17, 2019, fixing the issue in PC-Doctor Toolbox version 7.3 and later [1]. Almost all affected users were automatically upgraded [1]. Users should ensure automatic updates are enabled or manually check for updates within the product [1]. Dell also released a security advisory for Dell SupportAssist [2]. No other workarounds are documented; the fix is the recommended mitigation.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- PC-Doctor/PC-Doctor Toolboxdescription
- Range: <7.3
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
8- packetstormsecurity.com/files/153374/PC-Doctor-Toolbox-DLL-Hijacking.htmlmitrex_refsource_MISC
- seclists.org/fulldisclosure/2019/Jun/29mitremailing-listx_refsource_FULLDISC
- www.pc-doctor.com/company/pr-articles/130-pc-doctor-responds-to-software-vulnerability-reportmitrex_refsource_CONFIRM
- www.securityfocus.com/bid/108880mitrevdb-entryx_refsource_BID
- safebreach.com/Press-Post/SafeBreach-Identifies-Serious-Vulnerability-In-PC-Doctor-Softwaremitrex_refsource_MISC
- seclists.org/fulldisclosure/2019/Jun/29mitrex_refsource_MISC
- www.dell.com/support/article/il/en/ilbsdt1/sln317291/dsa-2019-084-dell-supportassist-for-business-pcs-and-dell-supportassist-for-home-pcs-security-update-for-pc-doctor-vulnerabilitymitrex_refsource_MISC
- www.us-cert.gov/ncas/current-activity/2019/06/21/Dell-Releases-Security-Advisory-Dell-SupportAssistmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.