DSA-2025-315: Security Update for Dell SupportAssist OS Recovery for Multiple Vulnerabilities

Summary: Dell SupportAssist OS Recovery remediation is available for multiple vulnerabilities that could be exploited by malicious users to compromise the affected system.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

High

Details

Proprietary Code CVE

Description

CVSS Base Score

CVSS Vector String

CVE-2025-38747

Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissions vulnerability. A local authenticated attacker could potentially exploit this vulnerability, leading to Elevation of Privileges.

7.8

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

CVE-2025-38746

Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.

3.5

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NThis hyperlink is taking you to a website outside of Dell Technologies.

 

Proprietary Code CVE

Description

CVSS Base Score

CVSS Vector String

CVE-2025-38747

Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissions vulnerability. A local authenticated attacker could potentially exploit this vulnerability, leading to Elevation of Privileges.

7.8

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

CVE-2025-38746

Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.

3.5

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NThis hyperlink is taking you to a website outside of Dell Technologies.

 

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Product

Affected Versions

Remediated Versions

Release date (MM/DD/YYYY)

Link

Dell SupportAssist OS Recovery

Versions prior to 5.5.14.0

Version 5.5.14.0 or later

08/05/2025

https://www.dell.com/support/kbdoc/en-us/000177401/restore-your-system-using-dell-supportassist-os-recovery

 

Product

Affected Versions

Remediated Versions

Release date (MM/DD/YYYY)

Link

Dell SupportAssist OS Recovery

Versions prior to 5.5.14.0

Version 5.5.14.0 or later

08/05/2025

https://www.dell.com/support/kbdoc/en-us/000177401/restore-your-system-using-dell-supportassist-os-recovery

 

Dell SupportAssist OS Recovery application assists in Disk Cloning, Reset, Repair functions.

To verify your device is running the remediated version of Dell SupportAssist OS Recovery, follow below steps:

  1. During boot, press F12 to enter boot settings.
  2. Select the SupportAssist OS Recovery option in boot menu.
  3. On load, in splash screen or from the About menu, verify the version information in the launched application.
  4. If version is 5.5.14.0 or later, then your device is running the remediated version.

OR

  1. Goto Control Panel -> Programs and Features.
  2. Check the version information for Dell SupportAssist Remediation.
  3. If version is 5.5.14.0 or later, then your device is running the remediated version.

If the version is lower than 5.5.14.0 version, please follow below steps to install the 5.5.14.0 version or later:

  1. Launch Dell SupportAssist OS Recovery application from Windows Start menu.
  2. Click on Update Software in Home page.
  3. Select the checkbox for “Check for Updates”.
  4. Click on Start button to install update.

Revision History

Revision

Date

Description

1.0

2025-08-06

Initial Release

 

Acknowledgements

CVE-2025-38747: Dell Technologies would like to thank falconCorrup for reporting this issue.

CVE-2025-38746: Dell Technologies would like to thank bugzzzhunter for reporting this issue.

Related Information

Affected Products

SupportAssist OS Recovery
Article Properties
Article Number: 000353093
Article Type: Dell Security Advisory
Last Modified: 06 Aug 2025
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.