CVE-2022-34387
Description
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privilege escalation vulnerability. A local authenticated malicious user could potentially exploit this vulnerability to elevate privileges and gain total control of the system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Dell SupportAssist contains a local privilege escalation vulnerability that lets an authenticated attacker gain total system control.
Vulnerability
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privilege escalation vulnerability. The bug resides in proprietary code and requires the attacker to have local authenticated access to the system. The exact component or function is not detailed in the available references [1].
Exploitation
A local authenticated malicious user can exploit this vulnerability by executing code or following a specific sequence of actions that leverage the flaw. The CVSS vector (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H) indicates the attack complexity is high and the attacker must already have high privileges, suggesting the escalation allows moving from a high-privilege account to full system control [1].
Impact
If successfully exploited, the attacker achieves privilege escalation and gains total control of the system. This results in a full compromise of confidentiality, integrity, and availability (CIA) of the affected system, with a CVSS base score of 6.4 (Medium) [1].
Mitigation
Dell released a security update for SupportAssist. For Home PCs, version 3.11.5 or later contains the fix; for Business PCs, version 3.3.0 or later contains the fix. Users should update to these versions as instructed in the Dell support bulletin DSA-2022-190 [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Range: <=3.2.0
- Range: <=3.11.4
- Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.dell.com/support/kbdoc/000204114mitrevendor-advisory
News mentions
0No linked articles in our index yet.