Dell TechnologiesCVE-2026-63693
Dell Client BIOS contains an Improper Link Resolution Before File Access
Medium6.6CVE-2026-63693 · Published Aug 24, 2026 · updated Aug 28, 2026
Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary Write
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Alienware Area 51m R2 Product | < 1.37.0 | 1.37.0 |
| Alienware Area-51 AAT2265 Product | < 1.8.1 | 1.8.1 |
| Alienware Aurora R13 Product | < 1.33.0 | 1.33.0 |
| Alienware Aurora R15 Product | < 1.29.0 | 1.29.0 |
| Alienware Aurora R15 AMD Product | < 1.26.0 | 1.26.0 |
| Alienware Aurora Ryzen Edition R14 Product | < 2.32.0 | 2.32.0 |
| Alienware m15 R3 Product | < 1.37.0 | 1.37.0 |
| Alienware m15 R4 Product | < 1.35.0 | 1.35.0 |
| Alienware m17 R3 Product | < 1.37.0 | 1.37.0 |
| Alienware m17 R4 Product | < 1.35.0 | 1.35.0 |
| Alienware x15 R1 Product | < 1.34.0 | 1.34.0 |
| Alienware x17 R1 Product | < 1.34.0 | 1.34.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-379
More Dell Technologies advisories
All Dell Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 26 | Dell Technologies PowerProtect One: stack buffer overflow | High7.5 | 20.3.0.0 |
| Aug 26 | Dell Technologies Cyber Recovery: SQL injection | Medium6.5 | Power Protect Cyber Recovery 20.3.0.0+2 more |
| Aug 26 | Dell Technologies iDRAC9: improper access control | Medium5.9 | 7.20.30.50 or later+1 more |
| Aug 26 | Dell Technologies Cloud Disaster Recovery: command injection | High7.2 | CDR 20.3 |
| Aug 26 | Dell Technologies Cloud Disaster Recovery: command injection | Critical9.1 | CDR 20.3 |
| Aug 24 | Dell Technologies ThinOS 10: improper access control | High7.8 | 2605_10.2518 |