CVE-2025-46685
Unknown
Unknown - Not Provided
Insecure Temporary File Permissions in Dell SupportAssist OS Recovery Enables Privilege Escalation
Publication date: 2026-01-13
Last updated on: 2026-02-13
Assigner: Dell
Description
Description
Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| dell | supportassist_os_recovery | to 5.5.15.1 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-378 | Opening temporary files without appropriate measures or controls can leave the file, its contents and any function that it impacts vulnerable to attack. |