Incorrect Privilege Assignment in Dell SupportAssist for Home and Business PCs
CVE-2025-36613
2.8LOW
What is CVE-2025-36613?
The vulnerability affects Dell SupportAssist for Home PCs and Business PCs, allowing low-privileged attackers with local access to gain unauthorized permissions. This misconfiguration can compromise system integrity and expose sensitive data, highlighting the importance of timely updates and security measures to mitigate risks.
Affected Version(s)
SupportAssist for Home PCs < 4.8.2.38851
References
CVSS V3.1
Score:
2.8
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dell would like to thank Ouallaout Noureddine for reporting this issue.