Impact
The vulnerability resides in Dell Command Update (DCU) versions prior to 5.7.1 and involves the deserialization of untrusted data. Exploitation of this flaw allows an adversary to execute arbitrary code within the context of the application, leading to the elevation of privileges on the affected system. The weakness is categorized under CWE‑502, indicating that untrusted data is deserialized without sufficient validation.
Affected Systems
Dell Command Update for Dell systems, any installation of the DCU software with a version earlier than 5.7.1. The vulnerability impacts any configuration where the DCU executable can be run by a local user without additional security controls.
Risk and Exploitability
With a CVSS score of 7.8, the risk level is moderate to high. The EPSS score is currently not available, and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. The likely attack vector is a local attacker who has low privileged access to the machine; because the flaw requires the DCU binary to be executed, the attacker would need to perform or trigger a local run of the application to achieve privilege escalation.
OpenCVE Enrichment