Executive brief
Dell Inventory Collector, a component used by various Dell support and update tools to identify system hardware, contains a security flaw. A person with low-level access to a computer could exploit this to write data to restricted files. This could potentially allow an attacker to disrupt system operations or gain higher-level control over the device.
Technical details
Dell Inventory Collector Client, integrated into several Dell management suites (SupportAssist, Optimizer, Command | Update, etc.), is vulnerable to an Improper Link Resolution Before File Access ('Link Following') bug, specifically involving Windows Junctions or Mount Points (CWE-1386). A local, low-privileged attacker can exploit this by creating symbolic links or junctions that redirect the application's file operations to a target file of the attacker's choosing. Successful exploitation leads to an arbitrary file write with the privileges of the Inventory Collector service. The vulnerability is addressed in version 13.8.0, which is typically delivered via automatic updates through the parent Dell software suites.
Affected products
- Dell Inventory Collector Client prior to 13.8.0
- Dell SupportAssist for PCs (Home and Business)
- Dell Optimizer
- Dell Trusted Device
- Dell Update / Alienware Update
- Dell Command | Update
- Dell Alienware Command Center
Timeline
- 2026-04-30: patched: Remediated version 13.8.0 released
- 2026-06-08: advisory: Initial Dell advisory DSA-2026-215 published
- 2026-06-09: disclosed: NVD publication date