DSA-2025-456: Security Update for Dell SupportAssist OS Recovery for Multiple Creation of Temporary File With Insecure Permissions Vulnerabilities

Summary: Dell SupportAssist OS Recovery remediation is available for multiple Creation of Temporary File with Insecure Permissions vulnerabilities that could be exploited by malicious users to compromise the affected system. ...

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

High

Details

Proprietary Code CVEs

Description

CVSS Base Score

CVSS Vector String

CVE-2025-46684

Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Tampering.

6.6

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

CVE-2025-46685

Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

7.5

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

 

Proprietary Code CVEs

Description

CVSS Base Score

CVSS Vector String

CVE-2025-46684

Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Tampering.

6.6

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

CVE-2025-46685

Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

7.5

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

 

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Product

Affected Versions

Remediated Versions

Release date (MM/DD/YYYY)

Link

Dell SupportAssist OS Recovery

Versions prior to 5.5.15.1

Version 5.5.15.1 or later

12/16/2025

https://www.dell.com/support/kbdoc/000177401/restore-your-system-using-dell-supportassist-os-recovery

 

Product

Affected Versions

Remediated Versions

Release date (MM/DD/YYYY)

Link

Dell SupportAssist OS Recovery

Versions prior to 5.5.15.1

Version 5.5.15.1 or later

12/16/2025

https://www.dell.com/support/kbdoc/000177401/restore-your-system-using-dell-supportassist-os-recovery

 

Dell SupportAssist OS Recovery application assists in Disk Cloning, Reset, Repair functions. 

Sell SupportAssist OS Recovery Plugin for Dell Update assists in installing or updating the Dell SupportAssist OS Recovery application to the latest version.  

To verify your device is running the remediated version of Dell SupportAssist OS Recovery Plugin, follow below steps:

  1. Goto Control Panel -> Programs and Features.
  2. Check the version information for Dell SupportAssist OS Recovery Plugin for Dell Update.
  3. If version is 5.5.15.1 or later, then your device is running the remediated version.

 

If the version is lower than 5.5.15.1 version, please follow below steps to install the 5.5.15.1 version or later:

  1. Launch Dell SupportAssist application from Windows Start menu.
  2. Click on Update Software in Home page.
  3. Select the checkbox for “Check for Updates”.
  4. Latest Dell SupportAssist OS Recovery Plugin for Dell Update will be listed for update
  5. Click on Start button to install update.

Revision History

Revision

Date

Description

1.0

2026-01-12

Initial Release

 

Acknowledgements

Dell Technologies would like to thank falconCorrup for reporting these issues.

Related Information

Affected Products

SupportAssist OS Recovery
Article Properties
Article Number: 000401506
Article Type: Dell Security Advisory
Last Modified: 12 Jan 2026
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.