Impact
The vulnerability is a Least Privilege Violation that allows an attacker with local, low-level access to raise their privileges on a system running Dell Alienware Command Center. According to the CVE description, exploitation could lead to an attacker gaining higher privileges than originally granted, potentially enabling further unauthorized actions such as modifying system settings or installing malicious software. The weakness aligns with CWE-272, which indicates a flaw in enforcing correct privilege levels for authorized actions.
Affected Systems
Dell Alienware Command Center (AWCC) versions prior to 6.13.8.0 are affected. The vulnerability applies to all installations of AWCC that have not been updated beyond this version threshold, regardless of the operating system or deployment configuration.
Risk and Exploitability
The CVSS score of 5.3 reflects a moderate severity assessment. The EPSS score is not available, so the likelihood of exploitation in the wild is unknown. The vulnerability is not listed in the CISA KEV catalog, indicating it has not been identified as a currently exploited vulnerability. Exploitation requires local, low-privilege access, suggesting that it is primarily a threat to users who have physical or local network access to the target machine. The attacker would need to execute privileged operations through the AWCC application in order to elevate their rights.
OpenCVE Enrichment