VYPR
Unrated severityNVD Advisory· Published Feb 10, 2023· Updated Mar 26, 2025

CVE-2022-34385

CVE-2022-34385

Description

SupportAssist for Home PCs (version 3.11.4 and prior) and  SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SupportAssist for Home and Business PCs has a cryptographic weakness that allows an authenticated non-admin user to obtain sensitive information.

Vulnerability

SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a cryptographic weakness vulnerability [1]. The issue resides in the proprietary code components of these products, which handle sensitive data using insufficiently secure cryptographic mechanisms [1]. An authenticated non-admin user can potentially exploit this weakness to obtain sensitive information [1].

Exploitation

Exploitation requires an attacker to be an authenticated non-admin user on the local system [1]. The attacker must be able to execute code or perform actions within the context of the SupportAssist application [1]. The exact sequence of steps is not detailed in the available references, but the cryptographic weakness likely allows the attacker to decrypt or bypass protection of sensitive data stored or transmitted by the product [1].

Impact

Upon successful exploitation, an attacker can obtain sensitive information, leading to a confidentiality impact of High [1]. The CVSS vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N indicates no impact on integrity or availability [1]. The attacker gains access to data that should be protected, potentially including credentials, personal data, or other confidential information [1].

Mitigation

Dell has released security updates to address this vulnerability [1]. For SupportAssist for Home PCs, users should update to version 3.11.5 or later; for SupportAssist for Business PCs, update to version 3.2.1 or later [1]. The Dell advisory DSA-2022-190 provides download links and further details [1]. No workarounds are currently available, and users are advised to apply the patch as soon as possible [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.