CVE-2025-36600

8.2

Dell · Client Platform BIOS

A BIOS-level vulnerability in Dell Client Platform BIOS allows a high-privileged local attacker to potentially achieve code execution via improper access control to memory regions.

Executive summary

A critical security vulnerability in Dell Client Platform BIOS versions prior to 1.51.0 poses a risk of code execution by high-privileged local attackers.

Vulnerability

The flaw involves improper access control applied to mirrored or aliased memory regions within an externally developed component of the BIOS. This vulnerability requires the attacker to possess high privileges and local access to the system to trigger the flaw.

Business impact

The potential for unauthorized code execution at the BIOS level presents a severe risk to system integrity and data confidentiality. Given the CVSS score of 8.2, this vulnerability is classified as High severity, as it could allow an attacker to bypass operating system security controls and gain persistent, low-level control over the affected hardware.

Remediation

Immediate Action: Administrators must update the Dell Client Platform BIOS to version 1.51.0 or later as specified in the official vendor advisory.

Proactive Monitoring: Security teams should monitor system logs for unusual administrative activity or unauthorized attempts to access sensitive hardware configurations.

Compensating Controls: Ensure that physical access to servers and workstations is strictly controlled, as the vulnerability requires local access to exploit.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Due to the deep-level nature of BIOS vulnerabilities, the risk of total system compromise is significant. Organizations should prioritize the deployment of the 1.51.0 firmware update across all affected Dell client platforms to neutralize this vector, as BIOS-level exploits are notoriously difficult to detect and remediate once successfully executed.

More Dell CVEs

Sources

Originally found and disclosed by Dell Technologies would like to thank BINARLY REsearch team for reporting this issue., per the CVE Program record.