#VU118588 Out-of-bounds write in ControlVault3 Plus and ControlVault3 - CVE-2025-36462
Published: November 18, 2025
ControlVault3 Plus
ControlVault3
Dell
Description
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input in the ControlVault WBDI Driver Broadcom Storage Adapter functionality within WBIO_USH_CREATE_CHALLENGE. A local user can use a specially crafted WinBioControlUnit call, trigger an out-of-bounds write and execute arbitrary code on the target system.