DSA-2025-442: Security Update for Dell Encryption for Multiple Improper Link Resolution Before File Access Vulnerabilities
Zusammenfassung: Dell Encryption remediation is available for multiple Improper Link Resolution Before File Access vulnerabilities that could be exploited by malicious users to compromise the affected system. ...
Auswirkungen
High
Weitere Angaben
This issue occurs only during the installation of Dell Encryption versions earlier than 11.12.1. If you already have Dell Encryption version prior to 11.12.1 installed, you do not need to reinstall, as the vulnerability exists in the installer process only—not the installed application.
Details
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2025-46637 |
Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A local malicious user could potentially exploit this vulnerability, leading to Elevation of privileges. |
7.3 |
|
|
CVE-2025-46636 |
Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. |
6.6 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2025-46637 |
Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A local malicious user could potentially exploit this vulnerability, leading to Elevation of privileges. |
7.3 |
|
|
CVE-2025-46636 |
Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. |
6.6 |
Betroffene Produkte und Korrektur
|
Product |
Affected Versions |
Remediated Versions |
Release Date |
Link |
|
Dell Encryption |
Versions prior to 11.12.1 |
Version 11.12.1 and later |
11/25/2025 |
|
Product |
Affected Versions |
Remediated Versions |
Release Date |
Link |
|
Dell Encryption |
Versions prior to 11.12.1 |
Version 11.12.1 and later |
11/25/2025 |
Revisionsverlauf
|
Revision |
Date |
Description |
|
1.0 |
2025-12-08 |
Initial Release |
Danksagung
Dell Technologies would like to thank falconCorrup for reporting these issues