Dell now has two security issues

Dell is having a bad week after two security flaws were found this week. Brendan Fay, principal information security consultant, Ward Solutions commented on the first flaw stating:

“A Dell certificate known as eDellRoot, installed by Dell Foundation Services, on many PCs has unintentionally introduced a security vulnerability, which could have adverse effects on users.

“The vulnerability has the potential to manipulate the trust certificate on affected PCs. This certificate is a common feature on all computers and serves to verify that websites you’re visiting are legitimate. eDellRoot opens up the possibility that a third party could trick the cert and allow websites that contain malware – or that might steal sensitive information – to masquerade as the legitimate website you’re looking for.

“Users need to be vigilant – perpetrators can be highly skilled at making fake websites look legitimate. Any user who has Dell Foundation Services on their PC should uninstall the eDellRoot cert from their computer entirely – just deleting it won’t suffice.”

Ward solutions have published a guide on their blog which shows you how you can check to see if you are affected. You can read their blog here.

The second security flaw is very similar to the first one since it also involves Dell installing a self-signed certificate and a private key on its customer’s computers. Once the certificate and a private key is installed, a little bit of reverse engineering, can allow a cybercriminal to spy on users’ encrypted Internet traffic, or to steal their sensitive information.

Dell have warned that anyone who used the “detect product” function on the company’s support site for the month spanning between Oct. 20 and Nov. 24 is likely to be affected. Further information on the two flaws and how to patch your computer have been issued by Dell and can be found here.

Ronan Leonard

Recent Posts

Origina to Create 350 New Jobs as Part of Global Expansion Supported by Enterprise Ireland

Dublin-based IT services and consulting company Origina today announced a significant expansion of its operations in…

15 hours ago

Kalmar Partners with TCS for Strategic AI-powered Transformation of its Enterprise IT Landscape

Tata Consultancy Services (TCS), a leading global IT services, consulting, and business solutions company, operating…

16 hours ago

Marine Institute’s SmartBay to play key role in evolving European ocean monitoring system

A new international study has proposed an operational strategy to advance the Digital Twin of…

17 hours ago

8 Irish game developers to launch game prototypes through pioneering IndieDev Fund

Irish game developers’ ability to punch above their weight in the competitive international games industry,…

19 hours ago

IT, Finance, and Construction top salary rankings according to IrishJobs

Leading hiring platform IrishJobs has today published new data that reveals professionals in the IT…

22 hours ago

Ireland cements position as Europe’s leading GDPR enforcer

Global law firm DLA Piper has today published the eighth edition of its annual GDPR…

4 days ago

More about Irish Tech News


Irish Tech News are Ireland’s No. 1 Online Tech Publication and often Ireland’s No.1 Tech Podcast too.


You can find hundreds of fantastic previous episodes and subscribe using whatever platform you like via our Anchor.fm page here: https://anchor.fm/irish-tech-news


If you’d like to be featured in an upcoming Podcast email us at Simon@IrishTechNews.ie now to discuss.


Irish Tech News have a range of services available to help promote your business. Why not drop us a line at Info@IrishTechNews.ie now to find out more about how we can help you reach our audience.


You can also find and follow us on Twitter, LinkedIn, Facebook, Instagram, TikTok and Snapchat.