Description
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.
Published: 2026-08-12
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Display and Peripheral Manager (DDPM) for Windows, in versions before 2.3.0.17, contains an authentication bypass flaw that allows an attacker with local, low‑privilege access to spoof authentication credentials. By exploiting this weakness the attacker can create or access administrative accounts, thereby gaining the ability to execute arbitrary code with elevated privileges. The vulnerability directly compromises integrity and confidentiality of the system, and can lead to full system compromise.

Affected Systems

All Dell DDPM Windows installations with a version earlier than 2.3.0.17 are affected. Users of older DDPM releases should review their system configuration and ensure that their installations match the corrected version.

Risk and Exploitability

The CVSS score of 7.8 classifies the vulnerability as high severity. No EPSS score is currently available, but the lack of public exploitation reports and the requirement for local access suggest that the exploitation probability is not high. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local with low privileges, requiring that the attacker already has a user account on the target machine. Once the authentication bypass is achieved, the attacker can elevate privileges to full control of the device.

Generated by OpenCVE AI on August 12, 2026 at 22:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell security update for DDPM Windows, which includes the fix for version 2.3.0.17 or later, from the Dell Knowledge Base at the provided URL.
  • If an update cannot be applied immediately, limit local user privileges and restrict administrative functionality of DDPM until a patch is deployed.
  • Use strong authentication controls and monitor for any unauthorized account creation or elevation of privileges in the system logs.

Generated by OpenCVE AI on August 12, 2026 at 22:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:display_and_peripheral_manager:*:*:*:*:*:windows:*:*

Thu, 13 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell display And Peripheral Manager
Vendors & Products Dell
Dell display And Peripheral Manager

Wed, 12 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass Enabling Local Privilege Escalation in Dell DDPM Windows

Wed, 12 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Display And Peripheral Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-13T03:56:04.066Z

Reserved: 2026-05-17T17:04:27.066Z

Link: CVE-2026-46731

cve-icon Vulnrichment

Updated: 2026-08-12T20:39:47.700Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T20:17:44.170

Modified: 2026-08-17T20:19:49.207

Link: CVE-2026-46731

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:15:07Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing