Impact
The Dell Monitor driver version 1.0.0.0 contains an improper link resolution before file access vulnerability, allowing local attackers to craft malicious paths that the driver follows to access files beyond the intended scope. This directory traversal failure can enable an attacker with lower privileges to read or modify system files, potentially granting them elevated rights. The weakness is classified as CWE‑59, which represents path traversal and link following errors that can compromise confidentiality, integrity, and availability when exploited.
Affected Systems
The vulnerability impacts the Dell Monitor driver version 1.0.0.0. No other Dell products or driver revisions are listed as affected in the CNA data.
Risk and Exploitability
The CVSS score of 6.6 indicates moderate severity. EPSS score 0.00113 indicates a very low exploitation probability, and the vulnerability is not listed in CISA KEV, meaning no confirmed public exploits are known. The attack vector is local; a user with low privileges must have physical or local access to the machine. If an attacker can influence the driver’s file path resolution, they may perform unauthorized file operations that lead to privilege escalation.
OpenCVE Enrichment