Privilege Escalation Vulnerability in Dell ControlVault Driver
CVE-2025-31361

8.7HIGH

Key Information:

Vendor

Broadcom

Vendor
CVE Published:
17 November 2025

What is CVE-2025-31361?

A privilege escalation vulnerability has been identified in the Dell ControlVault's WBDI Driver, specifically in the functionality associated with the WinBioControlUnit API call. If exploited, this flaw enables unauthorized users to escalate their privileges, allowing for potentially malicious actions on affected systems. Versions prior to 5.15.14.19 for Dell ControlVault3 and prior to 6.2.36.47 for Dell ControlVault3 Plus are susceptible to this vulnerability, making it critical for affected users to implement security updates promptly to mitigate risks.

Affected Version(s)

BCM5820X NA

ControlVault3 0 < 5.15.14.19

ControlVault3 Plus 0 < 6.2.36.47

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Philippe Laulheret of Cisco Talos.
.
CVE-2025-31361 : Privilege Escalation Vulnerability in Dell ControlVault Driver