Impact
Dell Device Management Agent versions before 26.05 contain an Improper Link Resolution Before File Access flaw classified as CWE-59. The flaw allows a low‑privileged attacker with local access to potentially exploit link following to access files outside its intended area, which could lead to elevation of privileges on the host system.
Affected Systems
The vulnerability affects Dell Device Management Agent installations where the product version is earlier than 26.05. Devices running these older releases are susceptible, while newer releases are assumed to be fixed.
Risk and Exploitability
The CVSS score of 7.3 indicates a high‑severity condition. The EPSS score of less than 1% indicates a very low exploitation probability. Attack requires local presence with low privileges, and successful exploitation could lead to privilege escalation to a higher level of authority on the compromised system. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment