Incorrect Privilege Assignment in Dell SupportAssist for Home and Business PCs
CVE-2025-36613

2.8LOW

Key Information:

Vendor

Dell

Vendor
CVE Published:
14 August 2025

What is CVE-2025-36613?

The vulnerability affects Dell SupportAssist for Home PCs and Business PCs, allowing low-privileged attackers with local access to gain unauthorized permissions. This misconfiguration can compromise system integrity and expose sensitive data, highlighting the importance of timely updates and security measures to mitigate risks.

Affected Version(s)

SupportAssist for Home PCs < 4.8.2.38851

References

CVSS V3.1

Score:
2.8
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dell would like to thank Ouallaout Noureddine for reporting this issue.
.