CVE-2021-36297 - CVE House
Back to Database
Status published High CVE-2021-36297

SupportAssist Client version 3.8 and 3.9 contains an Untrusted search...

Vulnerability Description

SupportAssist Client version 3.8 and 3.9 contains an Untrusted search path vulnerability that allows attackers to load an arbitrary .dll file via .dll planting/hijacking, only by a separate administrative action that is not a default part of the SOSInstallerTool.exe installation for executing arbitrary dll's,

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-36297

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

SupportAssist Client Consumer
Vulnerable Versions:
3.8, 3.9

Timeline

Official Publish: September 28th, 2021
Last Modified: September 16th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)