Description
Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Published: 2026-08-03
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Dell Monitor driver version 1.0.0.0 contains an improper link resolution before file access vulnerability, allowing local attackers to craft malicious paths that the driver follows to access files beyond the intended scope. This directory traversal failure can enable an attacker with lower privileges to read or modify system files, potentially granting them elevated rights. The weakness is classified as CWE‑59, which represents path traversal and link following errors that can compromise confidentiality, integrity, and availability when exploited.

Affected Systems

The vulnerability impacts the Dell Monitor driver version 1.0.0.0. No other Dell products or driver revisions are listed as affected in the CNA data.

Risk and Exploitability

The CVSS score of 6.6 indicates moderate severity. EPSS score 0.00113 indicates a very low exploitation probability, and the vulnerability is not listed in CISA KEV, meaning no confirmed public exploits are known. The attack vector is local; a user with low privileges must have physical or local access to the machine. If an attacker can influence the driver’s file path resolution, they may perform unauthorized file operations that lead to privilege escalation.

Generated by OpenCVE AI on August 4, 2026 at 21:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Acquire and install any Dell‑supported driver update that addresses the link‑follow issue.
  • Restrict local user privileges to the minimum required so that path traversal cannot reach privileged directories.
  • Monitor system event logs for unusual file access attempts that may indicate exploitation, and enforce strict file permissions to block traversal paths.

Generated by OpenCVE AI on August 4, 2026 at 21:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell monitor Driver
Vendors & Products Dell
Dell monitor Driver

Tue, 04 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Elevated Privileges via Improper Link Resolution in Dell Monitor Driver

Mon, 03 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Weaknesses CWE-59
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-05T13:33:46.424Z

Reserved: 2026-04-15T05:04:31.838Z

Link: CVE-2026-40717

cve-icon Vulnrichment

Updated: 2026-08-03T20:14:43.557Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-03T18:16:38.907

Modified: 2026-08-07T15:14:55.180

Link: CVE-2026-40717

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:21:54Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')