DSA-2025-292: Security Update for Dell Encryption and Dell Security Management Server for an Improper Link Resolution Vulnerability
Summary: Dell Encryption and Dell Security Management Server remediations are available for an Improper Link Resolution vulnerability that could be exploited by malicious users to compromise the affected system. ...
Impact
High
Details
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2025-36611 |
Dell Encryption and Dell Security Management Server, versions prior to 11.11.0, contain an Improper Link Resolution Before File Access ('Link Following') Vulnerability. A local malicious user could potentially exploit this vulnerability, leading to privilege escalation. |
7.3 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2025-36611 |
Dell Encryption and Dell Security Management Server, versions prior to 11.11.0, contain an Improper Link Resolution Before File Access ('Link Following') Vulnerability. A local malicious user could potentially exploit this vulnerability, leading to privilege escalation. |
7.3 |
Affected Products & Remediation
|
Product |
Affected Versions |
Remediated Versions |
Release Date (MM/DD/YYYY) |
Link |
|
Dell Encryption |
Versions prior to 11.11.0.1 |
Version 11.11.01 or later |
07/28/2025 |
|
|
Dell Security Management Server |
Versions prior to 11.11.0.2 |
Version 11.11.0.2 or later |
07/28/2025 |
|
Product |
Affected Versions |
Remediated Versions |
Release Date (MM/DD/YYYY) |
Link |
|
Dell Encryption |
Versions prior to 11.11.0.1 |
Version 11.11.01 or later |
07/28/2025 |
|
|
Dell Security Management Server |
Versions prior to 11.11.0.2 |
Version 11.11.0.2 or later |
07/28/2025 |
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2025-07-28 |
Initial Release |
Acknowledgements
Dell would like to thank falconCorrup for reporting this issue.