Impact
Dell PowerPath for Windows includes an Improper Privilege Management vulnerability (CWE-269). The flaw allows a local user with lower privileges to elevate their privileges, potentially gaining authority beyond what is intended. The elevated privileges could permit unauthorized configuration changes or execution of privileged code on the host system.
Affected Systems
Dell PowerPath versions 7.2 through 8.0 SP1 deployed on Windows systems are affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. An EPSS score of < 1% indicates a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires local access; a low privileged user must be present on the machine to trigger the privilege escalation. No remote exploitation pathway is described in the available data.
OpenCVE Enrichment