CVE-2025-43991

MEDIUM

SupportAssist <4.8.2-4.5.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

SupportAssist for Home PCs versions 4.8.2 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain an UNIX Symbolic Link (Symlink) following vulnerability. A low privileged attacker with local access to the system could potentially exploit this vulnerability to delete arbitrary files only in that affected system.

Scores

CVSS v3 6.3
EPSS 0.0001
EPSS Percentile 2.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-61
Status published
Products (2)
dell/supportassist_for_business_pcs < 4.5.3.25254
dell/supportassist_for_home_pcs < 4.8.2.29006
Published Oct 13, 2025
Tracked Since Feb 18, 2026