Incorrect Default Permissions in Dell PowerProtect Data Manager for Hyper-V
CVE-2025-43887

7HIGH

Key Information:

Vendor

Dell

Vendor
CVE Published:
10 September 2025

What is CVE-2025-43887?

The PowerProtect Data Manager from Dell is affected by an Incorrect Default Permissions vulnerability that exists in versions 19.19 and 19.20. This issue could allow low privileged attackers with local access to exploit the system, potentially leading to unauthorized elevation of privileges. It is crucial for users to apply the relevant security updates to mitigate the risk associated with this vulnerability.

Affected Version(s)

PowerProtect Data Manager < 19.21 build 11

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.