CVE-2025-38747

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/08/2025
Last modified:
18/08/2025

Description

Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissions vulnerability. A local authenticated attacker could potentially exploit this vulnerability, leading to Elevation of Privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:supportassist_os_recovery:*:*:*:*:*:*:*:* 5.5.14.0 (excluding)


References to Advisories, Solutions, and Tools