PT-2025-47225 · Dell · Dell Controlvault3 Plus+1

Philippe Laulheret

·

Published

2025-11-17

·

Updated

2025-11-18

·

CVE-2025-31361

CVSS v3.1

8.7

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Dell ControlVault3 versions prior to 5.15.14.19 Dell ControlVault3 Plus versions prior to 6.2.36.47
Description A privilege escalation issue exists in the ControlVault WBDI Driver's WBIO USH ADD RECORD functionality. A crafted WinBioControlUnit call can allow an attacker to escalate privileges. The attacker issues an API call to trigger this issue.
Recommendations Dell ControlVault3 versions prior to 5.15.14.19 should be updated to version 5.15.14.19 or later. Dell ControlVault3 Plus versions prior to 6.2.36.47 should be updated to version 6.2.36.47 or later.

Fix

LPE

Use of Uninitialized Resource

Weakness Enumeration

Related Identifiers

CVE-2025-31361

Affected Products

Dell Controlvault3
Dell Controlvault3 Plus