DSA-2025-205: Security Update for Dell Client Platform BIOS for an Improper Access Control Vulnerability
Summary: Dell Client Platform BIOS remediation is available for an Improper Access Control Vulnerability in an externally developed component that could be exploited by malicious users to compromise the affected system. ...
Impact
High
Details
|
CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2025-36600 |
Dell Client Platform BIOS contains an Improper Access Control Applied to Mirrored or Aliased Memory Regions vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution. |
8.2 |
|
CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2025-36600 |
Dell Client Platform BIOS contains an Improper Access Control Applied to Mirrored or Aliased Memory Regions vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution. |
8.2 |
Affected Products & Remediation
|
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Release Date (MM/DD/YYYY) |
Link |
|
Latitude 12 Rugged Extreme 7214 |
BIOS |
Versions prior to 1.51.0 |
Version 1.51.0 or later |
07/07/2025 |
|
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Release Date (MM/DD/YYYY) |
Link |
|
Latitude 12 Rugged Extreme 7214 |
BIOS |
Versions prior to 1.51.0 |
Version 1.51.0 or later |
07/07/2025 |
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2025-07-07 |
Initial Release |
Acknowledgements
Dell Technologies would like to thank BINARLY REsearch team for reporting this issue.