Impact
Dell Command Update (DCU) versions earlier than 5.7.1 contain an Incorrect Default Permissions flaw that allows a local user with low privileges to read or modify files and directories associated with DCU. This misconfiguration enables the attacker to gain unauthorized access to the host’s filesystem, potentially escalating privileges or tampering with system configurations. The vulnerability is classified as a CWE‑276 issue involving improper use of permissions.
Affected Systems
The affected product is Dell Command Update (DCU) sold by Dell. Any installation of DCU prior to version 5.7.1 is impacted. Systems that use those older releases and have DCU files stored in its installation directories are at risk. The Dell security advisory confirms that the issue is fixed in DCU 5.7.1 and later, and customers are advised to upgrade to a patched version.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity for local privilege escalation. EPSS score of 0.00093 (approximately 0.093%) indicates a very low probability of exploitation in the wild; the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is local access by a low‑privileged user, who can exploit the permissive file permissions to access sensitive DCU files or directories and potentially gain elevated privileges or modify system settings.
OpenCVE Enrichment