CNNVD-202510-1664 Information

CNNVD ID

CNNVD-202510-1664

CVE-2025-43991

  • CNNVD Published: 2025-10-13

Description (Chinese)

Dell SupportAssist for Business PCs和Dell SupportAssist for Home PCs都是美国戴尔(Dell)公司的产品。Dell SupportAssist for Business PCs是一款适用于企业电脑的客户端应用程序。该程序提供自动化、主动和预测性技术进行故障排除等。Dell SupportAssist for Home PCs是一款适用于家庭电脑的客户端应用程序。该程序提供自动化、主动和预测性技术进行故障排除等。 Dell SupportAssist for Home PCs 4.8.2及之前版本和Dell SupportAssist for Business PCs 4.5.3及之前版本存在安全漏洞,该漏洞源于UNIX符号链接跟随问题,可能导致本地低权限攻击者删除受影响系统中的任意文件。

Description (English)

Dell SupportAssist for Business PCs and Dell SupportAssist for Home PCs are products of Dell, United States. Dell SupportAssist for Business PCs is a client application for enterprise computers. It provides automation, proactive and predictive technology for troubleshooting, etc. Dell SupportAssist for Home PCs is a client application for home computers. It provides automation, proactive and predictive technology for troubleshooting, etc. There is a security loophole in Dell SupportAssist for Home PCs 4.8.2 and earlier versions and Dell SupportAssist for Business PCs 4.5.3 and earlier versions, which stems from the UNIX symbol link follow-up problem and may result in local low-authorized attackers removing any files from the affected system.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

戴尔

Published

2025-10-13

Last Modified

2026-02-24

References

https://www.dell.com/support/kbdoc/en-us/000378367/dsa-2025-362-security-update-for-dell-supportassist-for-home-pcs-and-dell-supportassist-for-business-pcs-vulnerabilities

Patch

https://www.dell.com/support/kbdoc/en-us/000378367/dsa-2025-362-security-update-for-dell-supportassist-for-home-pcs-and-dell-supportassist-for-business-pcs-vulnerabilities

Share on: