CVE-2025-43991

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/10/2025
Last modified:
04/11/2025

Description

SupportAssist for Home PCs versions 4.8.2 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain an UNIX Symbolic Link (Symlink) following vulnerability. A low privileged attacker with local access to the system could potentially exploit this vulnerability to delete arbitrary files only in that affected system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:supportassist_for_business_pcs:*:*:*:*:*:*:*:* 4.5.3.25254 (excluding)
cpe:2.3:a:dell:supportassist_for_home_pcs:*:*:*:*:*:*:*:* 4.8.2.29006 (excluding)