CVE-2025-36613
Dell SupportAssist for PCs vulnerability analysis and mitigation

Overview

CVE-2025-36613 is an Incorrect Privilege Assignment vulnerability (CWE-266) in Dell SupportAssist for Home PCs and Dell SupportAssist for Business PCs. It affects SupportAssist for Home PCs versions 4.6.3 and prior, and SupportAssist for Business PCs versions 4.5.3 and prior. The vulnerability was published on August 14, 2025, with a patch advisory released by Dell on August 18, 2025. It carries a CVSS v3.1 base score of 7.8 (High), reflecting local exploitation by a low-privileged attacker with no user interaction required (Dell Advisory).

Technical details

The vulnerability is classified as CWE-266 (Incorrect Privilege Assignment), meaning the software incorrectly assigns elevated privileges to a process or user, enabling unauthorized access beyond what is intended. An attacker with low-privileged local access can exploit this flaw without requiring user interaction, potentially escalating their privileges on the affected system. The attack vector is local, with low attack complexity, making exploitation straightforward for any authenticated local user on a vulnerable system (Dell Advisory).

Impact

Successful exploitation of this vulnerability could result in high impacts to confidentiality, integrity, and availability on the affected system, as reflected in the CVSS v3.1 score. A low-privileged local attacker could gain unauthorized access to sensitive data, modify system configurations or files, and potentially disrupt system availability. The scope is limited to the affected host (unchanged scope), but privilege escalation could enable further lateral movement or persistence within an enterprise environment (Dell Advisory).

Mitigation and workarounds

Dell has released patched versions to address this vulnerability. Users should update as follows:

  • SupportAssist for Home PCs: Upgrade to version 4.8.2.38851 or later.
  • SupportAssist for Business PCs: Upgrade to version 4.9.0 or later.

Additional hardening steps include limiting local user access and privileges, implementing strict access controls, and monitoring system logs for unauthorized modification attempts (Dell Advisory).

Additional resources


SourceThis report was generated using AI

Related Dell SupportAssist for PCs vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-52535HIGH8.8
  • Dell SupportAssist for PCs logoDell SupportAssist for PCs
  • cpe:2.3:a:dell:supportassist_for_home_pcs
NoYesDec 25, 2024
CVE-2025-38738HIGH7.8
  • Dell SupportAssist for PCs logoDell SupportAssist for PCs
  • cpe:2.3:a:dell:supportassist_for_home_pcs
NoYesAug 14, 2025
CVE-2025-36613HIGH7.8
  • Dell SupportAssist for PCs logoDell SupportAssist for PCs
  • cpe:2.3:a:dell:supportassist_for_home_pcs
NoYesAug 14, 2025
CVE-2024-38305HIGH7.3
  • Dell SupportAssist for PCs logoDell SupportAssist for PCs
  • cpe:2.3:a:dell:supportassist_for_home_pcs
NoYesAug 21, 2024
CVE-2025-43991HIGH7.1
  • Dell SupportAssist for PCs logoDell SupportAssist for PCs
  • cpe:2.3:a:dell:supportassist_for_home_pcs
NoYesOct 13, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management