Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
High

Out-of-bounds write in Dell ControlVault3 cv_upgrade_sensor_firmware

IdentifiersCVE-2025-25050CWE-787· Out-of-bounds Write

CVE-2025-25050 is an out-of-bounds write vulnerability in the cv_upgrade_sensor_firmware functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault 3 Plus prior to 6.2.26.36. According to the provided content, a specially crafted ControlVault API call can trigger improper bounds handling in this firmware code path, resulting in a write outside the intended memory buffer. The issue affects ControlVault firmware exposed through the host-accessible ControlVault API surface and is part of the broader ReVault set of ControlVault3 vulnerabilities identified by Cisco Talos.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation can corrupt adjacent firmware memory and may destabilize the ControlVault firmware. In the broader ControlVault3 attack context described in the supporting content, firmware memory-corruption vulnerabilities can be leveraged toward arbitrary code execution in the privileged ControlVault firmware environment. That in turn may enable extraction of device key material, malicious firmware modification, persistence that survives OS reinstallation, weakening or bypass of biometric protections such as Windows Hello fingerprint verification, and potential pivoting back into the host OS through trusted ControlVault/WinBio paths.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, reduce exposure by limiting access to ControlVault APIs and the affected device to trusted users only, disabling unused ControlVault-related functionality or peripherals where operationally feasible, and monitoring for abnormal access to the ControlVault device interface, unexpected loading of bcmbipdll.dll by unusual processes, and crashes in related Broadcom or Windows Biometric services. In environments with elevated physical risk, additional hardening such as disabling fingerprint login and enabling chassis-intrusion protections may reduce attack opportunities, but these measures do not replace firmware updates.

Remediation

Patch, then assume compromise.

Upgrade Dell ControlVault3 firmware to version 5.15.10.14 or later, and Dell ControlVault 3 Plus firmware to version 6.2.26.36 or later. Apply Dell-provided updates through Windows Update or Dell support channels as appropriate for the affected platform. Because the issue is in firmware, remediation requires installing the corrected firmware release on affected systems.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity8

Community discussion across Reddit, Mastodon, and other social sources.