DSA-2025-051: Security Update for Dell SupportAssist OS Recovery for a Symbolic Link Attack Vulnerability
요약: Dell SupportAssist OS Recovery remediation is available for a Symbolic Link Attack Vulnerability that could be exploited by malicious users to compromise the affected system.
영향
High
세부 정보
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2025-22480 |
Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary file deletion and Elevation of Privileges. |
7.0 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2025-22480 |
Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary file deletion and Elevation of Privileges. |
7.0 |
영향을 받는 제품 및 문제 해결
|
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Release Date |
Link |
|
Dell SupportAssist OS Recovery |
Software |
Versions prior to 5.5.13.1 |
Versions 5.5.13.1 or later |
02/04/2025 |
|
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Release Date |
Link |
|
Dell SupportAssist OS Recovery |
Software |
Versions prior to 5.5.13.1 |
Versions 5.5.13.1 or later |
02/04/2025 |
Dell SupportAssist OS Recovery auto-updates to the latest version. To verify the version, please follow the steps:
- Go to Control Panel.
- Programs -> Programs and Features.
- Find "Dell SupportAssist Remediation" and "Dell SupportAssist OS Recovery Plugin".
- Verify that the version of these programs is 5.5.13.1 or later.
Alternatively, if the Dell SupportAssist OS Recovery is launched, please check the version from “About” on the application.
For more info, please refer to https://www.dell.com/support/kbdoc/en-sc/000197387/how-to-identify-the-dell-supportassist-os-recovery-version
해결 방법 및 완화 방안
None
개정 내역
|
Revision |
Date |
Description |
|
1.0 |
2025-02-13 |
Initial Release |
감사의 말
CVE-2025-22480 : Dell Technologies would like to thank mdanilor for reporting this issue.