DSA-2025-296: Security Update for Dell SupportAssist for Home PCs and Dell SupportAssist for Business PCs vulnerabilities

Summary: Dell SupportAssist for Home and Business PCs Software remediation is available for Privilege Escalation vulnerabilities that could be exploited by malicious users to compromise that affected system only. ...

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

Medium

Additional Details

For CVE-2025-38738, the fix for SupportAssistInstaller.exe v4.8.2.38851 has been deployed to systems in production which remediate new installations and future upgrades for SupportAssist for Home PCs. Customers are not required to take any action and should not uninstall or reinstall SupportAssist for Home PCs that is already on their systems. The vulnerability is active only during the installation process and does not have any attack vectors after the installation is completed. It does not impact any version of already installed Support Assist for Home PCs.

Details

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2025-38738 SupportAssist for Home PCs Installer exe version(s) 4.8.2.29006 and prior, contain(s) an Incorrect Privilege Assignment vulnerability in the Installer. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
CVE-2025-36612 SupportAssist for Business PCs, version(s) 4.5.3 and prior, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
CVE-2025-36613 SupportAssist for Home PCs versions 4.6.3 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access. 2.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:NThis hyperlink is taking you to a website outside of Dell Technologies.

 

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2025-38738 SupportAssist for Home PCs Installer exe version(s) 4.8.2.29006 and prior, contain(s) an Incorrect Privilege Assignment vulnerability in the Installer. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
CVE-2025-36612 SupportAssist for Business PCs, version(s) 4.5.3 and prior, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
CVE-2025-36613 SupportAssist for Home PCs versions 4.6.3 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access. 2.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:NThis hyperlink is taking you to a website outside of Dell Technologies.

 

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Product Affected Versions Remediated Versions Link
SupportAssist for Home PCs Versions prior to 4.8.2.29006 Version 4.8.2.38851 or later https://www.dell.com/support/contents/article/product-support/self-support-knowledgebase/software-and-downloads/support-assist/supportassist-for-home
SupportAssist for Business PCs Versions prior to 4.5.3 Version 4.9.0 or later https://www.dell.com/lp/dt/supportassist-business-PC

 

Product Affected Versions Remediated Versions Link
SupportAssist for Home PCs Versions prior to 4.8.2.29006 Version 4.8.2.38851 or later https://www.dell.com/support/contents/article/product-support/self-support-knowledgebase/software-and-downloads/support-assist/supportassist-for-home
SupportAssist for Business PCs Versions prior to 4.5.3 Version 4.9.0 or later https://www.dell.com/lp/dt/supportassist-business-PC

 

Revision History

RevisionDateDescription
1.02025-08-14Initial Release

 

Acknowledgements

CVE-2025-38738, CVE-2025-36612, CVE-2025-36613: Dell would like to thank Ouallaout Noureddine for reporting this issue.

Related Information

Affected Products

SupportAssist, SupportAssist for Home PCs, SupportAssist for Business PCs
Article Properties
Article Number: 000356690
Article Type: Dell Security Advisory
Last Modified: 14 Aug 2025
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.