---
id: CVE-2025-46637
title: >-
  Dell Encryption, versions prior to 11.12.1, contain an Improper Link
  Resolution Before File Access ('Link Following') vulnerability
summary: >-
  Dell Encryption, versions prior to 11.12.1, contain an Improper Link
  Resolution Before File Access ('Link Following') vulnerability. A local
  malicious user could potentially exploit this vulnerability, leading to
  Elevation of privileges.
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-59
vendor: dell
product: encryption
affected:
  - encryption < 11.12.1
patched:
  - encryption 11.12.1
published: '2025-12-09'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T10:10:00.227'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-46637'
references:
  - url: 'https://www.dell.com/support/kbdoc/en-us/000394657/dsa-2025-442'
    label: security_alert@emc.com
tags:
  - nvd
epss: 0.00103
epssPercentile: 0.00913
ingestedAt: '2026-10-08T10:28:24.300Z'
---

## Overview

Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A local malicious user could potentially exploit this vulnerability, leading to Elevation of privileges.

## Affected

- `encryption < 11.12.1`

## Remediation

Upgrade past the affected range:

- `encryption 11.12.1`
