Impact
Dell Client BIOS contains an Improper Link Resolution Before File Access (Link Following) vulnerability. A low-privileged attacker with local access could exploit this flaw to perform an arbitrary write to arbitrary files on the system.
Affected Systems
Affected Dell computer models include Aurora R16, Alienware Area 51m R2, Alienware Area-51 AAT2265, Aurora R13, Aurora R15, Aurora R15 AMD, Aurora Ryzen Edition R14, m15 R3, m15 R4, m17 R3, m17 R4, x15 R1, x17 R1, Inspiron 15 3510, Inspiron 15 3521, XPS 8950, and XPS 8960. No specific BIOS version numbers are provided; the issue applies to the BIOS firmware on these systems.
Risk and Exploitability
The CVSS score is 6.6, indicating moderate severity, and the EPSS score is not available. This vulnerability is listed in no KEV catalog. Based on the description, the attacker must have local access and low privileges, and the attack vector is inferred to be local. The exploit would allow an attacker to write to arbitrary locations before the BIOS performs file access.
OpenCVE Enrichment