Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary file deletion and Elevation of Privileges.
References
Link | Resource |
---|---|
https://www.dell.com/support/kbdoc/en-us/000275712/dsa-2025-051 | Vendor Advisory |
Configurations
History
18 Feb 2025, 18:39
Type | Values Removed | Values Added |
---|---|---|
First Time |
Dell
Dell supportassist |
|
Summary |
|
|
CPE | cpe:2.3:a:dell:supportassist:*:*:*:*:*:*:*:* | |
References | () https://www.dell.com/support/kbdoc/en-us/000275712/dsa-2025-051 - Vendor Advisory | |
CWE | CWE-59 |
13 Feb 2025, 16:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-13 16:16
Updated : 2025-02-18 18:39
NVD link : CVE-2025-22480
Mitre link : CVE-2025-22480
CVE.ORG link : CVE-2025-22480
JSON object : View
Products Affected
dell
- supportassist