Impact
The vulnerability is a Deserialization of Untrusted Data flaw in Dell Command Update that can be triggered by a low‑privileged local user. By crafting malicious input, the attacker can gain elevated rights on the system, potentially allowing full control over the affected machine. This flaw corresponds to CWE‑502 and, if exploited, could compromise the confidentiality, integrity, or availability of local resources.
Affected Systems
Dell Command Update (DCU) versions before 5.7.1 are vulnerable.
Risk and Exploitability
This flaw has a CVSS score of 7.8, indicating high severity. The EPSS score of 0.00113 indicates an extremely low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalogue. Since the description specifies a low‑privileged local user as the attacker, the most likely attack vector is a local exploitation path; remote exploitation is not suggested by the information provided. Because the flaw involves deserialization of untrusted data, a successful attack would enable an attacker to execute arbitrary code or commands within the context of the application, effectively escalating privileges on the host.
OpenCVE Enrichment