CVE-2025-38747

Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissions vulnerability. A local authenticated attacker could potentially exploit this vulnerability, leading to Elevation of Privileges.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:supportassist_os_recovery:*:*:*:*:*:*:*:*

History

18 Aug 2025, 15:36

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000353093/dsa-2025-315 - () https://www.dell.com/support/kbdoc/en-us/000353093/dsa-2025-315 - Vendor Advisory
Summary
  • (es) Dell SupportAssist OS Recovery, versiones anteriores a la 5.5.14.0, presenta una vulnerabilidad de creación de archivos temporales con permisos inseguros. Un atacante local autenticado podría explotar esta vulnerabilidad, lo que provocaría una elevación de privilegios.
First Time Dell
Dell supportassist Os Recovery
CPE cpe:2.3:a:dell:supportassist_os_recovery:*:*:*:*:*:*:*:*

06 Aug 2025, 20:23

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-06 20:15

Updated : 2025-08-18 15:36


NVD link : CVE-2025-38747

Mitre link : CVE-2025-38747

CVE.ORG link : CVE-2025-38747


JSON object : View

Products Affected

dell

  • supportassist_os_recovery
CWE
CWE-378

Creation of Temporary File With Insecure Permissions