DSA-2025-442: Security Update for Dell Encryption for Multiple Improper Link Resolution Before File Access Vulnerabilities
Summary: Dell Encryption remediation is available for multiple Improper Link Resolution Before File Access vulnerabilities that could be exploited by malicious users to compromise the affected system. ...
Impact
High
Additional Details
This issue occurs only during the installation of Dell Encryption versions earlier than 11.12.1. If you already have Dell Encryption version prior to 11.12.1 installed, you do not need to reinstall, as the vulnerability exists in the installer process only—not the installed application.
Details
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2025-46637 |
Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A local malicious user could potentially exploit this vulnerability, leading to Elevation of privileges. |
7.3 |
|
|
CVE-2025-46636 |
Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. |
6.6 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2025-46637 |
Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A local malicious user could potentially exploit this vulnerability, leading to Elevation of privileges. |
7.3 |
|
|
CVE-2025-46636 |
Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. |
6.6 |
Affected Products & Remediation
|
Product |
Affected Versions |
Remediated Versions |
Release Date |
Link |
|
Dell Encryption |
Versions prior to 11.12.1 |
Version 11.12.1 and later |
11/25/2025 |
|
Product |
Affected Versions |
Remediated Versions |
Release Date |
Link |
|
Dell Encryption |
Versions prior to 11.12.1 |
Version 11.12.1 and later |
11/25/2025 |
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2025-12-08 |
Initial Release |
Acknowledgements
Dell Technologies would like to thank falconCorrup for reporting these issues