Description
Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Published: 2026-08-19
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Command Update contains a Time‑of‑check Time‑of‑use race condition that can allow a local, low‑privileged user to elevate privileges. An attacker who can initiate the vulnerable operation on a host running an affected version can manipulate the timing of file or value checks to cause the program to act on a malicious or altered resource, thereby violating the intended privilege boundary. The core weakness is a race condition, classified as CWE‑367, that directly undermines the integrity of privilege checks within the updater.

Affected Systems

The vulnerability affects Dell Command Update (DCU) installations with a version earlier than 5.7.1 on any operating system compatible with the tool. Users of DCU should verify that their deployments are running 5.7.1 or a later release to avoid this flaw.

Risk and Exploitability

The vulnerability scores a CVSS of 7.8, indicating high severity for local exploitation. The EPSS score of 0.00084 (0.08%) shows an extremely low likelihood of exploitation, and the flaw is not listed in the CISA KEV catalog, yet it still poses a significant risk for environments that allow local users to run DCU operations. Because the attack requires local access and low privilege, the attack surface is limited to physically or logically accessible systems. However, if such access is obtained, an attacker can gain elevated rights, potentially compromising the entire host.

Generated by OpenCVE AI on August 20, 2026 at 15:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell Command Update version 5.7.1 or later to all affected systems.
  • Restrict local user accounts that can run DCU, ensuring only trusted administrators have permission.
  • Enforce least‑privilege principles on the host and consider additional endpoint protection that monitors for abnormal file operation timing.

Generated by OpenCVE AI on August 20, 2026 at 15:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via TOCTOU Race Condition in Dell Command Update

Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell dell Command Update (dcu)
Vendors & Products Dell
Dell dell Command Update (dcu)

Thu, 20 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Time‑of‑check Time‑of‑use Race Condition in Dell Command Update Allows Local Privilege Escalation

Wed, 19 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Time‑of‑check Time‑of‑use Race Condition in Dell Command Update Allows Local Privilege Escalation

Wed, 19 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Weaknesses CWE-367
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Dell Command Update (dcu)
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-19T20:00:10.002Z

Reserved: 2026-06-09T17:04:35.249Z

Link: CVE-2026-53477

cve-icon Vulnrichment

Updated: 2026-08-19T19:55:33.949Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T15:17:10.417

Modified: 2026-08-20T13:02:12.153

Link: CVE-2026-53477

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T15:30:03Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition