Vulnerabilities in the ControlVault3 firmware affect over 100 Dell laptop models
Dell has published a security advisory and warned of five vulnerabilities (CVE-2025-24311, CVE-2025-25215, CVE-2025-24922, CVE-2025-25050, CVE-2025-24919) that affect the ControlVault3 loaded on at least 100 laptop models of the company. An attacker could exploit some of these vulnerabilities to trigger elevation of privilege, arbitrary code execution and security restriction bypass on the targeted system. All five vulnerabilities were discovered by Cisco Talos researchers and patches have now been released to address these vulnerabilities.
More information on vulnerabilities and updates is available in Dell security advisory – dell.com
11 August 2025