6.6

CVE-2026-63693

Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary Write
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerDell
≫
Produkt Alienware Area 51m R2
Default Statusunaffected
Version 0
Version < 1.37.0
Status affected
HerstellerDell
≫
Produkt Alienware Area-51 AAT2265
Default Statusunaffected
Version 0
Version < 1.8.1
Status affected
HerstellerDell
≫
Produkt Alienware Aurora R13
Default Statusunaffected
Version 0
Version < 1.33.0
Status affected
HerstellerDell
≫
Produkt Alienware Aurora R15
Default Statusunaffected
Version 0
Version < 1.29.0
Status affected
HerstellerDell
≫
Produkt Alienware Aurora R15 AMD
Default Statusunaffected
Version 0
Version < 1.26.0
Status affected
HerstellerDell
≫
Produkt Alienware Aurora Ryzen Edition R14
Default Statusunaffected
Version 0
Version < 2.32.0
Status affected
HerstellerDell
≫
Produkt Alienware m15 R3
Default Statusunaffected
Version 0
Version < 1.37.0
Status affected
HerstellerDell
≫
Produkt Alienware m15 R4
Default Statusunaffected
Version 0
Version < 1.35.0
Status affected
HerstellerDell
≫
Produkt Alienware m17 R3
Default Statusunaffected
Version 0
Version < 1.37.0
Status affected
HerstellerDell
≫
Produkt Alienware m17 R4
Default Statusunaffected
Version 0
Version < 1.35.0
Status affected
HerstellerDell
≫
Produkt Alienware x15 R1
Default Statusunaffected
Version 0
Version < 1.34.0
Status affected
HerstellerDell
≫
Produkt Alienware x17 R1
Default Statusunaffected
Version 0
Version < 1.34.0
Status affected
HerstellerDell
≫
Produkt AURORA R16
Default Statusunaffected
Version 0
Version < 2.25.0
Status affected
HerstellerDell
≫
Produkt Inspiron 15 3510
Default Statusunaffected
Version 0
Version < 1.30.0
Status affected
HerstellerDell
≫
Produkt Inspiron 15 3521
Default Statusunaffected
Version 0
Version < 1.25.0
Status affected
HerstellerDell
≫
Produkt XPS 8950
Default Statusunaffected
Version 0
Version < 1.33.0
Status affected
HerstellerDell
≫
Produkt XPS 8960
Default Statusunaffected
Version 0
Version < 2.24.0
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.1% 0.01
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
EMC 6.6 1.3 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
CWE-379 Creation of Temporary File in Directory with Insecure Permissions

The product creates a temporary file in a directory whose permissions allow unintended actors to determine the file's existence or otherwise access that file.

https://www.dell.com/support/kbdoc/en-us/000501826/dsa-2026-280-security-update-for-dell-client-platform-bios-for-an-improper-link-resolution-before-file-access-link-following-vulnerability