CVE-2025-22480

Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary file deletion and Elevation of Privileges.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:supportassist:*:*:*:*:*:*:*:*

History

18 Feb 2025, 18:39

Type Values Removed Values Added
First Time Dell
Dell supportassist
Summary
  • (es) Las versiones de Dell SupportAssist OS Recovery anteriores a la 5.5.13.1 contienen una vulnerabilidad de ataque de enlace simbólico. Un atacante con pocos privilegios y acceso local podría aprovechar esta vulnerabilidad, lo que provocaría la eliminación arbitraria de archivos y la elevación de privilegios.
CPE cpe:2.3:a:dell:supportassist:*:*:*:*:*:*:*:*
References () https://www.dell.com/support/kbdoc/en-us/000275712/dsa-2025-051 - () https://www.dell.com/support/kbdoc/en-us/000275712/dsa-2025-051 - Vendor Advisory
CWE CWE-59

13 Feb 2025, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-13 16:16

Updated : 2025-02-18 18:39


NVD link : CVE-2025-22480

Mitre link : CVE-2025-22480

CVE.ORG link : CVE-2025-22480


JSON object : View

Products Affected

dell

  • supportassist
CWE
CWE-61

UNIX Symbolic Link (Symlink) Following

CWE-59

Improper Link Resolution Before File Access ('Link Following')