Impact
Dell Command Update versions prior to 5.7.1 allow a local attacker to follow an improperly resolved link, resulting in unauthorized file access. This vulnerability can be abused to escape normal privilege boundaries on the system, potentially granting the attacker higher privileges than it originally held. The flaw aligns with CWE-59, which captures unsafe relative path resolution leading to unintended file access.
Affected Systems
Dell Command Update (DCU) software from Dell, affecting all deployments using a release older than 5.7.1. Users running these versions are susceptible, regardless of the motherboard or OEM environment, as the vulnerable component operates with local machine resources.
Risk and Exploitability
The vulnerability is rated a CVSS score of 6.6, indicating moderate severity, and it is not listed in the CISA KEV catalog. The EPSS score of 0.00123 indicates a very low probability of exploitation. Although the local attack vector and low privilege requirement mean an attacker who can access the machine locally may trigger the flaw to elevate privileges, the overall likelihood remains low.
OpenCVE Enrichment