CVE-2025-22480: Dell Supportassist OS Recovery

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary file deletion and Elevation of Privileges.

Affected products

  • Dell Supportassist OS Recovery: before 5.5.13.1 (fixed in 5.5.13.1)

Published 2025-02-13. Last modified 2026-06-17.