CVE-2025-31361
BaseFortify
Publication date: 2025-11-17
Last updated on: 2025-11-17
Assigner: Talos
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| dell | controlvault3 | * |
| dell | controlvault3_plus | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-908 | The product uses or accesses a resource that has not been initialized. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a privilege escalation issue in the ControlVault WBDI Driver's WBIO_USH_ADD_RECORD functionality for Dell ControlVault3 and ControlVault3 Plus. An attacker can exploit this by issuing a specially crafted WinBioControlUnit API call, which can lead to gaining higher privileges than intended.
How can this vulnerability impact me? :
The vulnerability can allow an attacker with limited privileges to escalate their privileges on the affected system. This can lead to unauthorized access, potential control over sensitive operations, and increased risk of further exploitation or damage.