Improper Access Control in Dell Client Platform BIOS
CVE-2025-36600

8.2HIGH

Key Information:

Vendor

Dell

Vendor
CVE Published:
8 July 2025

Badges

📈 Score: 140👾 Exploit Exists📰 News Worthy

What is CVE-2025-36600?

CVE-2025-36600 is a serious vulnerability affecting the Dell Client Platform BIOS, which is designed to facilitate system-level interactions and management for Dell laptops and desktops. The vulnerability arises from an improper access control mechanism related to certain memory regions. If exploited by a high-privileged attacker with local access, this issue could enable them to execute arbitrary code on the affected systems. This could lead to unauthorized access, allowing the attacker to manipulate system functions and potentially gain control over sensitive data or disrupt operations, thereby posing a significant risk to organizational security.

Potential Impact of CVE-2025-36600

  1. Unauthorized System Access: An attacker could leverage this vulnerability to run unauthorized code on the BIOS level, gaining complete control over the affected device. This could facilitate a range of malicious activities, including unauthorized data access and manipulation.

  2. Data Breaches: With the ability to execute arbitrary code, attackers can access sensitive information stored on the device, which can lead to data breaches. This can significantly impact an organization's confidentiality, integrity, and overall credibility.

  3. Operational Disruption: By exploiting this vulnerability, an attacker could disrupt normal system operations, leading to potential downtime or degraded performance. This disruption could harm business processes and create a negative impact on productivity and revenue.

Affected Version(s)

Client Platform BIOS < 1.51.0

News Articles

CVE-2025-36600 Dell Client Platform BIOS improper access control applied to mirrored or aliased memory regions (dsa-2025-205)

A vulnerability has been found in Dell Client Platform BIOS up to 1.50.x and classified as critical. This vulnerability was named CVE-2025-36600. It is recommended to upgrade the affected component.

4 days ago

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • 📰

    First article discovered

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dell Technologies would like to thank BINARLY REsearch team for reporting this issue.
.
CVE-2025-36600 : Improper Access Control in Dell Client Platform BIOS