Impact
This vulnerability is a Missing Authentication for a critical function that allows an attacker who has local access with low privileges to potentially elevate their privileges to a higher level. Through exploitation, the attacker could gain additional system permissions, enabling further malicious activities. The flaw is categorized as CWE-306, indicating insufficient authentication.
Affected Systems
Dell Display and Peripheral Manager (DDPM) for Mac, versions prior to 2.3.0.1005, are affected. Users installed with these older releases are at risk unless updated to the latest secure version.
Risk and Exploitability
The CVSS score of 7.8 classifies the risk as High, and the vulnerability exists without an existing exploit in the public domain. The EPSS score of 0.00112 indicates a very low probability of exploitation. It is not listed in CISA KEV, implying no widely known active exploitation. The likely attack vector is a local attacker who can execute processes on the machine, and the impact is critical if privilege elevation is achieved.
OpenCVE Enrichment