CVE-2025-27688: High severity Dell ThinOS vulnerability
Published Mar 18, 2025
·Updated
Dell ThinOS 2408 and prior, contains an improper permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Affected Software
13 affected components
Dell ThinOS<2408
All of the following
Dell ThinOS<=2408
Any of the following
Dell Latitude 3420
Dell Latitude 3440
Dell Latitude 5440
Dell Latitude 5450
Dell Optiplex 3000 Thin Client
Dell Optiplex 5400 All-in-one
Dell Optiplex 7410 All-in-one
Dell Optiplex 7420 All-in-one
Dell Wyse 5070 Thin Client
Dell Wyse 5470 All-in-one Thin Client
Dell Wyse 5470 Mobile Thin Client
Event History
Mar 18, 2025
CVE Published
via MITRE·03:55 PM
Data Sourced
via MITRE·03:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-27688?
CVE-2025-27688 is classified as a low severity vulnerability.
2
How do I fix CVE-2025-27688?
To fix CVE-2025-27688, update your Dell ThinOS to version 2409 or later.
3
What type of vulnerability is CVE-2025-27688?
CVE-2025-27688 is an improper permissions vulnerability.
4
Who can exploit CVE-2025-27688?
A low privileged attacker with local access can potentially exploit CVE-2025-27688.
5
What could be the consequence of CVE-2025-27688 exploitation?
Successful exploitation of CVE-2025-27688 could lead to elevation of privileges.