CVE-2025-22480: High severity dell supportassist vulnerability
Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary file deletion and Elevation of Privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22480?
CVE-2025-22480 is classified as a low-severity vulnerability due to its requirements for local access and its limited impact.
How do I fix CVE-2025-22480?
To fix CVE-2025-22480, update Dell SupportAssist OS Recovery to version 5.5.13.1 or later.
What type of attack is CVE-2025-22480 associated with?
CVE-2025-22480 is associated with a symbolic link attack that can lead to file deletion and elevation of privileges.
Who is affected by CVE-2025-22480?
CVE-2025-22480 affects users of Dell SupportAssist OS Recovery versions prior to 5.5.13.1.
Can CVE-2025-22480 be exploited remotely?
CVE-2025-22480 cannot be exploited remotely; it requires local access by a low-privileged attacker.