CVE-2025-38747
7.8Dell · SupportAssist OS Recovery
Dell SupportAssist OS Recovery contains a vulnerability involving the creation of temporary files with insecure permissions, which could allow for privilege escalation.
Executive summary
A local authenticated attacker can exploit a file permission vulnerability in Dell SupportAssist OS Recovery to achieve elevation of privileges on the host system.
Vulnerability
This vulnerability is categorized as a creation of temporary file with insecure permissions (CWE-378). A local user with standard authentication can leverage this flaw to gain elevated system privileges.
Business impact
The potential for privilege escalation poses a significant risk to organizational security, as an attacker with standard access can bypass local security boundaries to gain administrative control. With a CVSS score of 7.8, this vulnerability is classified as High, reflecting the severe impact on confidentiality, integrity, and availability once an attacker elevates their privileges.
Remediation
Immediate Action: Update Dell SupportAssist OS Recovery to version 5.5.14.0 or later as specified in the official Dell security advisory (DSA-2025-315).
Proactive Monitoring: Audit system logs for unauthorized attempts to access or modify temporary directories or files created by the SupportAssist service.
Compensating Controls: Restrict local user access to the affected system and enforce the principle of least privilege to minimize the potential impact of a local escalation attempt.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the High severity rating and the potential for complete system compromise via privilege escalation, immediate patching is required. Organizations should prioritize updating all instances of Dell SupportAssist OS Recovery to the latest version to mitigate this risk and prevent unauthorized administrative access.
More Dell CVEs
Sources
Originally found and disclosed by Dell Technologies would like to thank falconCorrup for reporting this issue., per the CVE Program record.