CVE-2025-46602
📋 TL;DR
Dell SupportAssist OS Recovery versions before 5.5.15.0 can expose sensitive information to local low-privileged attackers through file/directory access. This vulnerability allows attackers with local access to potentially view sensitive data stored in externally accessible locations. Dell users with vulnerable versions of SupportAssist OS Recovery are affected.
💻 Affected Systems
- Dell SupportAssist OS Recovery
📦 What is this software?
⚠️ Risk & Real-World Impact
Worst Case
Sensitive system information, credentials, or configuration data could be extracted, potentially enabling further attacks or data breaches.
Likely Case
Local low-privileged users could access sensitive files containing system information or temporary data, leading to information disclosure.
If Mitigated
With proper access controls and patching, the vulnerability would be prevented from exposing sensitive information.
🎯 Exploit Status
Exploitation requires local access and low privileges; specific exploit details are not publicly documented.
🛠️ Fix & Mitigation
✅ Official Fix
Patch Version: 5.5.15.0 or later
Vendor Advisory: https://www.dell.com/support/kbdoc/en-us/000382443/dsa-2025-403
Restart Required: No
Instructions:
1. Download the latest version of Dell SupportAssist OS Recovery from Dell's official website. 2. Run the installer to update to version 5.5.15.0 or higher. 3. Verify the update completed successfully.
🔧 Temporary Workarounds
Restrict Local Access
allLimit local access to systems running Dell SupportAssist OS Recovery to trusted users only.
🧯 If You Can't Patch
- Uninstall Dell SupportAssist OS Recovery if not required for system functionality.
- Implement strict access controls and monitoring for local user activities on affected systems.
🔍 How to Verify
Check if Vulnerable:
Check the version of Dell SupportAssist OS Recovery installed; if it's below 5.5.15.0, the system is vulnerable.
Check Version:
Check the program version in Windows Settings > Apps or via the software's about section.
Verify Fix Applied:
Confirm that Dell SupportAssist OS Recovery is updated to version 5.5.15.0 or later.
📡 Detection & Monitoring
Log Indicators:
- Unusual file access attempts in system logs related to Dell SupportAssist directories.
Network Indicators:
- No network indicators as this is a local vulnerability.
SIEM Query:
Search for events related to file access in paths containing 'Dell' or 'SupportAssist' by non-admin users.