Incorrect Privilege Assignment in Dell SupportAssist for Home and Business PCs
CVE-2025-36613
7.8HIGH
What is CVE-2025-36613?
The vulnerability affects Dell SupportAssist for Home PCs and Business PCs, allowing low-privileged attackers with local access to gain unauthorized permissions. This misconfiguration can compromise system integrity and expose sensitive data, highlighting the importance of timely updates and security measures to mitigate risks.
Affected Version(s)
SupportAssist for Home PCs < 4.8.2.38851
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dell would like to thank Ouallaout Noureddine for reporting this issue.