CVE-2025-36600

Dell Client Platform BIOS contains an Improper Access Control Applied to Mirrored or Aliased Memory Regions vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dell:latitude_12_rugged_extreme_7214_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_12_rugged_extreme_7214:-:*:*:*:*:*:*:*

History

18 Aug 2025, 18:55

Type Values Removed Values Added
CPE cpe:2.3:o:dell:latitude_12_rugged_extreme_7214_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_12_rugged_extreme_7214:-:*:*:*:*:*:*:*
References () https://www.dell.com/support/kbdoc/en-us/000320876/dsa-2025-205 - () https://www.dell.com/support/kbdoc/en-us/000320876/dsa-2025-205 - Vendor Advisory
Summary
  • (es) Dell Client Platform BIOS contiene una vulnerabilidad de control de acceso inadecuado aplicado a regiones de memoria duplicadas o con alias en un componente desarrollado externamente. Un atacante con privilegios elevados y acceso local podría explotar esta vulnerabilidad, lo que provocaría la ejecución de código.
First Time Dell
Dell latitude 12 Rugged Extreme 7214
Dell latitude 12 Rugged Extreme 7214 Firmware

08 Jul 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-08 15:15

Updated : 2025-08-18 18:55


NVD link : CVE-2025-36600

Mitre link : CVE-2025-36600

CVE.ORG link : CVE-2025-36600


JSON object : View

Products Affected

dell

  • latitude_12_rugged_extreme_7214
  • latitude_12_rugged_extreme_7214_firmware
CWE
CWE-1257

Improper Access Control Applied to Mirrored or Aliased Memory Regions