CVE-2026-63693
6.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
Summary
Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary Write
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Dell | Alienware Area 51m R2 | 0 < 1.37.0 | affected |
| Dell | Alienware Area-51 AAT2265 | 0 < 1.8.1 | affected |
| Dell | Alienware Aurora R13 | 0 < 1.33.0 | affected |
| Dell | Alienware Aurora R15 | 0 < 1.29.0 | affected |
| Dell | Alienware Aurora R15 AMD | 0 < 1.26.0 | affected |
| Dell | Alienware Aurora Ryzen Edition R14 | 0 < 2.32.0 | affected |
| Dell | Alienware m15 R3 | 0 < 1.37.0 | affected |
| Dell | Alienware m15 R4 | 0 < 1.35.0 | affected |
| Dell | Alienware m17 R3 | 0 < 1.37.0 | affected |
| Dell | Alienware m17 R4 | 0 < 1.35.0 | affected |
| Dell | Alienware x15 R1 | 0 < 1.34.0 | affected |
| Dell | Alienware x17 R1 | 0 < 1.34.0 | affected |
| Dell | AURORA R16 | 0 < 2.25.0 | affected |
| Dell | Inspiron 15 3510 | 0 < 1.30.0 | affected |
| Dell | Inspiron 15 3521 | 0 < 1.25.0 | affected |
| Dell | XPS 8950 | 0 < 1.33.0 | affected |
| Dell | XPS 8960 | 0 < 2.24.0 | affected |
Weaknesses
- CWE-379: CWE-379: Creation of Temporary File in Directory with Insecure Permissions
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.