Impact
Dell Display and Peripheral Manager (DDPM) for Windows, in versions before 2.3.0.17, contains an authentication bypass flaw that allows an attacker with local, low‑privilege access to spoof authentication credentials. By exploiting this weakness the attacker can create or access administrative accounts, thereby gaining the ability to execute arbitrary code with elevated privileges. The vulnerability directly compromises integrity and confidentiality of the system, and can lead to full system compromise.
Affected Systems
All Dell DDPM Windows installations with a version earlier than 2.3.0.17 are affected. Users of older DDPM releases should review their system configuration and ensure that their installations match the corrected version.
Risk and Exploitability
The CVSS score of 7.8 classifies the vulnerability as high severity. No EPSS score is currently available, but the lack of public exploitation reports and the requirement for local access suggest that the exploitation probability is not high. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local with low privileges, requiring that the attacker already has a user account on the target machine. Once the authentication bypass is achieved, the attacker can elevate privileges to full control of the device.
OpenCVE Enrichment