Security News Pre-Installed Software Flaws Expose Dell Systems to Code Execution

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Forum Veteran
Feb 4, 2016
2,516
15,624
3,578
53
Germany / Poland
....a quote from the article:

Flaws in pre-installed software expose Dell systems to attacks that could result in the disabling of security mechanisms, privilege escalation, and arbitrary code execution within the context of the application user.
The vulnerable applications include the Dell Precision Optimizer application service software and Invincea-X and Invincea Dell Protected Workspace, Cisco Talos reveals in an advisory.
 
  • Like
Reactions: SumG and frogboy
It’s one thing to bundle a computer with junkware, but a complete other to bundle it with junkware that is a severe threat to anyone using the computer
 
  • Like
Reactions: LASER_oneXM
Happens more often than people realize too :( I bought a Razer laptop and found an unquoted service path in the Qualcomm drivers and there are no updates (luckily this is easy to fix yourself without a driver update). At work I had a Logitech wireless keyboard and it also was using unquoted service paths... it is 2017 this type of thing should not happen anymore ffs.

Don't get me started on DLLs
 
  • Like
Reactions: LASER_oneXM
It’s one thing to bundle a computer with junkware, but a complete other to bundle it with junkware that is a severe threat to anyone using the computer

Unfortunately these third party installs are a huge risk. One of the first things I do when I get a new laptop is to flatten it and fresh-install. Even then updates can sometimes re-install it. Voodooshield was blocking some background Lenovo crap on my wifes computer which I discovered was 'surveying' my network and running hidden Netsh commands every 15 minutes.. Talk about BS..

This isn't the first time Dell has put people at risk with their junkware/bloat.
 
  • Like
Reactions: LASER_oneXM