Dell’s firmware updating software, BIOSConnect, has been discovered to have a major security flaw, affecting 30 million devices that it came preinstalled on. The program is part of their SupportAssist program, made to allow for simpler updating and troubleshooting.

If exploited, the flaw could be used to subvert the normal boot process and circumvent system security controls, allowing a hacker to run malicious code and give them control of the device. In response, Dell has suggested users not use the BIOSConnect program to update their BIOS. Unfortunately, this leaves complex updates in the hands of normal users–and one misstep could lead to a bricked device.

FULL ARTICLE