Description
Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary Write
Published: 2026-08-24
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary Write
Action: Apply Patch
AI Analysis

Impact

Dell Client BIOS contains an Improper Link Resolution Before File Access (Link Following) vulnerability. A low-privileged attacker with local access could exploit this flaw to perform an arbitrary write to arbitrary files on the system.

Affected Systems

Affected Dell computer models include Aurora R16, Alienware Area 51m R2, Alienware Area-51 AAT2265, Aurora R13, Aurora R15, Aurora R15 AMD, Aurora Ryzen Edition R14, m15 R3, m15 R4, m17 R3, m17 R4, x15 R1, x17 R1, Inspiron 15 3510, Inspiron 15 3521, XPS 8950, and XPS 8960. No specific BIOS version numbers are provided; the issue applies to the BIOS firmware on these systems.

Risk and Exploitability

The CVSS score is 6.6, indicating moderate severity, and the EPSS score is not available. This vulnerability is listed in no KEV catalog. Based on the description, the attacker must have local access and low privileges, and the attack vector is inferred to be local. The exploit would allow an attacker to write to arbitrary locations before the BIOS performs file access.

Generated by OpenCVE AI on August 24, 2026 at 21:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download the DSA-2026-280 BIOS update from Dell support and run the MSI installer on the affected system with administrative rights, following the on-screen prompts.
  • Reboot the system to complete the BIOS firmware update.
  • Set a secure BIOS administrator password to restrict unauthorized BIOS configuration changes.

Generated by OpenCVE AI on August 24, 2026 at 21:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell alienware Area-51 Aat225
Dell alienware Area 51m R2
Dell alienware Aurora R13
Dell alienware Aurora R15
Dell alienware Aurora R15 Amd
Dell alienware Aurora Ryzen Edition R14
Dell alienware M15 R3
Dell alienware M15 R4
Dell alienware M17 R3
Dell alienware M17 R4
Dell alienware X15 R1
Dell alienware X17 R1
Dell aurora R16
Dell inspiron 15 3510
Dell inspiron 15 3521
Dell xps 8950
Dell xps 8960
Vendors & Products Dell
Dell alienware Area-51 Aat225
Dell alienware Area 51m R2
Dell alienware Aurora R13
Dell alienware Aurora R15
Dell alienware Aurora R15 Amd
Dell alienware Aurora Ryzen Edition R14
Dell alienware M15 R3
Dell alienware M15 R4
Dell alienware M17 R3
Dell alienware M17 R4
Dell alienware X15 R1
Dell alienware X17 R1
Dell aurora R16
Dell inspiron 15 3510
Dell inspiron 15 3521
Dell xps 8950
Dell xps 8960

Mon, 24 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Description Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary Write
Weaknesses CWE-379
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H'}


Subscriptions

Dell Alienware Area-51 Aat225 Alienware Area 51m R2 Alienware Aurora R13 Alienware Aurora R15 Alienware Aurora R15 Amd Alienware Aurora Ryzen Edition R14 Alienware M15 R3 Alienware M15 R4 Alienware M17 R3 Alienware M17 R4 Alienware X15 R1 Alienware X17 R1 Aurora R16 Inspiron 15 3510 Inspiron 15 3521 Xps 8950 Xps 8960
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-27T14:36:28.474Z

Reserved: 2026-07-17T17:05:09.170Z

Link: CVE-2026-63693

cve-icon Vulnrichment

Updated: 2026-08-27T14:27:11.355Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-24T20:16:55.677

Modified: 2026-08-28T15:29:44.967

Link: CVE-2026-63693

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T22:00:04Z

Weaknesses
  • CWE-379

    Creation of Temporary File in Directory with Insecure Permissions