CVE-2025-27688

Dell ThinOS 2408 and prior, contains an improper permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dell:thinos:*:*:*:*:*:*:*:*
OR cpe:2.3:h:dell:latitude_3420:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_3440:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_5440:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_5450:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:optiplex_3000_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:optiplex_5400_all-in-one:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:optiplex_7410_all-in-one:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:optiplex_7420_all-in-one:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_5070_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_5470_all-in-one_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_5470_mobile_thin_client:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-03-18 16:15

Updated : 2025-07-01 15:08


NVD link : CVE-2025-27688

Mitre link : CVE-2025-27688

CVE.ORG link : CVE-2025-27688


JSON object : View

Products Affected

dell

  • optiplex_5400_all-in-one
  • wyse_5470_mobile_thin_client
  • latitude_5450
  • latitude_3440
  • latitude_5440
  • optiplex_7420_all-in-one
  • wyse_5070_thin_client
  • wyse_5470_all-in-one_thin_client
  • latitude_3420
  • optiplex_3000_thin_client
  • thinos
  • optiplex_7410_all-in-one
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource