CVE-2023-28066: Dell OS Recovery Tool

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Dell OS Recovery Tool, versions 2.2.4013 and 2.3.7012.0, contain an Improper Access Control Vulnerability. A local authenticated non-administrator user could potentially exploit this vulnerability in order to elevate privileges on the system.

Affected products

  • Dell OS Recovery Tool: version 2.2.4013 only; version 2.3.7012.0 only

Published 2023-06-01. Last modified 2026-06-17.