DSA-2025-051: Security Update for Dell SupportAssist OS Recovery for a Symbolic Link Attack Vulnerability
Summary: Dell SupportAssist OS Recovery remediation is available for a Symbolic Link Attack Vulnerability that could be exploited by malicious users to compromise the affected system.
Impact
High
Details
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2025-22480 |
Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary file deletion and Elevation of Privileges. |
7.0 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2025-22480 |
Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary file deletion and Elevation of Privileges. |
7.0 |
Affected Products & Remediation
|
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Release Date |
Link |
|
Dell SupportAssist OS Recovery |
Software |
Versions prior to 5.5.13.1 |
Versions 5.5.13.1 or later |
02/04/2025 |
|
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Release Date |
Link |
|
Dell SupportAssist OS Recovery |
Software |
Versions prior to 5.5.13.1 |
Versions 5.5.13.1 or later |
02/04/2025 |
Dell SupportAssist OS Recovery auto-updates to the latest version. To verify the version, please follow the steps:
- Go to Control Panel.
- Programs -> Programs and Features.
- Find "Dell SupportAssist Remediation" and "Dell SupportAssist OS Recovery Plugin".
- Verify that the version of these programs is 5.5.13.1 or later.
Alternatively, if the Dell SupportAssist OS Recovery is launched, please check the version from “About” on the application.
For more info, please refer to https://www.dell.com/support/kbdoc/en-sc/000197387/how-to-identify-the-dell-supportassist-os-recovery-version
Workarounds & Mitigations
None
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2025-02-13 |
Initial Release |
Acknowledgements
CVE-2025-22480 : Dell Technologies would like to thank mdanilor for reporting this issue.