Impact
Detected in the Dell Server Update Utility, versions before 26.07.01, the vulnerability is an uncontrolled search path element flaw. A local attacker with limited permissions can influence the path that the utility follows when locating shared libraries or executable components, which may result in arbitrary code execution under the utility’s process context. The flaw is listed as CWE-427.
Affected Systems
Affects Dell Driver Pack for Linux OS and Dell Driver Pack for Windows OS, along with the Dell Server Update Utility on Linux 64‑bit and Windows 64‑bit formats. Any installation of the update utility with a version older than 26.07.01 is vulnerable.
Risk and Exploitability
The CVSS score of 8.2 marks the flaw as high severity, but the EPSS score is not available and the vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires local access and a low‑privileged user account; no remote vector is described. If the utility runs in a privileged context, an attacker could gain escalation to those privileges through the code execution path.
OpenCVE Enrichment