
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-36613 is an Incorrect Privilege Assignment vulnerability (CWE-266) in Dell SupportAssist for Home PCs and Dell SupportAssist for Business PCs. It affects SupportAssist for Home PCs versions 4.6.3 and prior, and SupportAssist for Business PCs versions 4.5.3 and prior. The vulnerability was published on August 14, 2025, with a patch advisory released by Dell on August 18, 2025. It carries a CVSS v3.1 base score of 7.8 (High), reflecting local exploitation by a low-privileged attacker with no user interaction required (Dell Advisory).
The vulnerability is classified as CWE-266 (Incorrect Privilege Assignment), meaning the software incorrectly assigns elevated privileges to a process or user, enabling unauthorized access beyond what is intended. An attacker with low-privileged local access can exploit this flaw without requiring user interaction, potentially escalating their privileges on the affected system. The attack vector is local, with low attack complexity, making exploitation straightforward for any authenticated local user on a vulnerable system (Dell Advisory).
Successful exploitation of this vulnerability could result in high impacts to confidentiality, integrity, and availability on the affected system, as reflected in the CVSS v3.1 score. A low-privileged local attacker could gain unauthorized access to sensitive data, modify system configurations or files, and potentially disrupt system availability. The scope is limited to the affected host (unchanged scope), but privilege escalation could enable further lateral movement or persistence within an enterprise environment (Dell Advisory).
Dell has released patched versions to address this vulnerability. Users should update as follows:
Additional hardening steps include limiting local user access and privileges, implementing strict access controls, and monitoring system logs for unauthorized modification attempts (Dell Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."