CVE-2025-36611

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
30/07/2025
Last modified:
14/01/2026

Description

Dell Encryption and Dell Security Management Server, versions prior to 11.11.0, contain an Improper Link Resolution Before File Access ('Link Following') Vulnerability. A local malicious user could potentially exploit this vulnerability, leading to privilege escalation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:encryption:*:*:*:*:*:*:*:* 11.11.0.1 (excluding)
cpe:2.3:a:dell:security_management_server:*:*:*:*:*:*:*:* 11.11.0.2 (excluding)


References to Advisories, Solutions, and Tools