📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Patch & vulnerability status

Dell Command Dell Inc.

Dell Command 5.6.25

Latest tracked version 5.6.25. Release status, tracked CVEs, and automated cross-platform patching for Dell Command.

PlatformLatest versionCVEs trackedLast checked
Windows5.6.25112025-03-26

Known vulnerabilities (CVEs) in Dell Command

Lavawall tracks 11 published CVEs affecting Dell Command, and deploys the versions that fix them automatically across your fleet.

CVEPublishedSeverityDetailsVector
CVE-2024-289622024-08-06 04:16:46MEDIUM (8)Dell Command | Update, Dell Update, and Alienware Update UWP, versions prior to 5.4, contain an Exposed Dangerous Method or Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.NETWORK
CVE-2023-280712023-06-23 11:15:10MEDIUM (7) Dell Command | Update, Dell Update, and Alienware Update versions 4.9.0, A01 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability to create arbitrary folder leading to permanent Denial of Service (DOS). LOCAL
CVE-2023-280652023-06-23 12:15:09MEDIUM (7) Dell Command | Update, Dell Update, and Alienware Update versions 4.8.0 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability leading to privilege escalation. LOCAL
CVE-2023-236982023-02-10 13:15:11MEDIUM (7) Dell Command | Update, Dell Update, and Alienware Update versions before 4.6.0 and 4.7.1 contain Insecure Operation on Windows Junction in the installer component. A local malicious user may potentially exploit this vulnerability leading to arbitrary file delete. LOCAL
CVE-2022-344592023-02-01 05:15:13HIGH (8) Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a improper verification of cryptographic signature in get applicable driver component. A local malicious user could potentially exploit this vulnerability leading to malicious payload execution. LOCAL
CVE-2022-344582023-02-01 05:15:12MEDIUM (7) Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in download operation component. A local malicious user could potentially exploit this vulnerability leading to the disclosure of confidential data. LOCAL
CVE-2022-343842023-02-11 01:23:24HIGH (8) Dell SupportAssist Client Consumer (version 3.11.1 and prior), SupportAssist Client Commercial (version 3.2 and prior), Dell Command | Update, Dell Update, and Alienware Update versions before 4.5 contain a Local Privilege Escalation Vulnerability in the Advanced Driver Restore component. A local malicious user may potentially exploit this vulnerability, leading to privilege escalation. LOCAL
CVE-2022-343822022-09-02 18:15:12HIGH (8)Dell Command Update, Dell Update and Alienware Update versions prior to 4.6.0 contains a Local Privilege Escalation Vulnerability in the custom catalog configuration. A local malicious user may potentially exploit this vulnerability in order to elevate their privileges.LOCAL
CVE-2022-244262022-04-01 20:15:08HIGH (8)Dell Command | Update, Dell Update, and Alienware Update version 4.4.0 contains a Local Privilege Escalation Vulnerability in the Advanced Driver Restore component. A local malicious user could potentially exploit this vulnerability, leading to privilege escalation.LOCAL
CVE-2019-37502019-12-03 21:15:12MEDIUM (6)Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\IC\ICDebugLog.txt" to any targeted file. This issue occurs because of insecure handling of Temp directory permissions that were set incorrectly.LOCAL
CVE-2019-37492019-12-03 21:15:11MEDIUM (6)Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\ICProgress\Dell_InventoryCollector_Progress.xml" to any targeted file. This issue occurs because permissions on the Temp directory were set incorrectly.LOCAL

Why keeping Dell Command patched matters

Unpatched third-party applications are one of the most common ways attackers get in: 57% of breached MSP clients and 32% of ransomware cases trace back to a missing patch. Every Dell Command release that fixes a security bug is public, so attackers see it too, and an out-of-date install becomes a documented way in. Tracking the installed version on every machine and closing the gap quickly is what turns a disclosed CVE into a non-event.

How Lavawall® patches Dell Command

Lavawall® watches Dell Command releases and CVEs continuously, ranks each update by risk, and deploys it across your whole fleet, Windows, macOS, and Linux, from a single agent, independently of your RMM. You get one place to see which machines are behind on Dell Command, one policy to bring them current, and timestamped evidence for audits.

Frequently asked questions

What is the latest version of Dell Command?
Lavawall tracks Dell Command at version 5.6.25 (last checked 2025-03-26). New releases are monitored continuously and can be deployed automatically across your fleet.
Does Dell Command have known security vulnerabilities (CVEs)?
Lavawall tracks 11 CVEs for Dell Command and remediates them automatically as part of patching.
How do I patch Dell Command automatically?
Deploy the Lavawall® agent and Dell Command updates are applied automatically across Windows, macOS, and Linux, risk-ranked and reported, independently of your RMM.

Lavawall® monitors releases and CVEs for Dell Command through public information and proprietary statistical analysis, and can patch it automatically across your fleet.