This application, known as Dell System Detect, is pre-installed with many Dell systems. According to research done by Tom Forbes
, older versions of Dell System Detect are vulnerable to a serious remote code execution attack.
What this basically means is that anyone with a vulnerable version of the tool (which maintains persistence on the system and therefore is always running) might be directed by an attacker to a specific website designed to exploit the flaw in the program and execute any commands the attacker wishes.
This could potentially lead to malware being installed without user awareness, stolen credentials, damaged system configuration and more.
Thankfully Dell has since modified this tool based on the research and it is no longer vulnerable, so itís in the best interest for everyone to update this tool
if they are running a computer designed by Dell.