Impact
Dell Display and Peripheral Manager for Windows is vulnerable to improper link resolution before file access, known as Link Following (CWE-59). A local attacker with low privileges could maliciously manipulate the installer or service to follow a crafted link, resulting in the ability to execute arbitrary code with elevated system privileges.
Affected Systems
The vulnerability affects Dell Display and Peripheral Manager (Windows) versions prior to 2.2. Users running these versions are at risk if the installer or service processes untrusted input. The issue applies to the Windows installation of the product.
Risk and Exploitability
The CVSS base score of 6.6 classifies the flaw as moderate severity, and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. Local access is required, and the attacker must have at least low system privileges to mount the attack, making remote exploitation unlikely. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog, further suggesting limited real-world exploitation.
OpenCVE Enrichment