Description
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.
Published: 2026-08-12
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Dell Display and Peripheral Manager (DDPM) Windows software contains an authentication bypass vulnerability that permits a spoofed credential attack. The flaw can be leveraged by a low‑privileged local user to elevate privileges and execute arbitrary code. This constitutes an authorization weakness (CWE‑284, CWE‑290) and can lead to system‑level compromise.

Affected Systems

Dell Display and Peripheral Manager (DDPM) Windows versions prior to 2.3.0.17 are affected. All editions under the Dell:Display and Peripheral Manager (DDPM Windows) vendor designation are vulnerable.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, while the EPSS score of 0.00129 (about 0.13%) indicates a very low but nonzero exploitation probability. The vulnerability is not listed in CISA KEV. The attack vector is local and requires a low‑privileged user. The CVE description does not cite a publicly available exploit, but the flaw still enables local privilege escalation and arbitrary code execution, posing a significant risk to affected systems.

Generated by OpenCVE AI on August 17, 2026 at 22:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell DSA‑2026‑320 security update to upgrade DDPM Windows to version 2.3.0.17 or newer.
  • If an update cannot be applied or the component is not required, uninstall or disable the Dell Display and Peripheral Manager from the system.
  • Disable any scheduled tasks or services associated with DDPM to reduce the attack surface.

Generated by OpenCVE AI on August 17, 2026 at 22:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass by Spoofing in Dell Display and Peripheral Manager (Windows) Leading to Privilege Escalation

Mon, 17 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-290
CPEs cpe:2.3:a:dell:display_and_peripheral_manager:*:*:*:*:*:windows:*:*

Thu, 13 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell display And Peripheral Manager
Vendors & Products Dell
Dell display And Peripheral Manager

Wed, 12 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass by Spoofing in Dell Display and Peripheral Manager (Windows) Leading to Privilege Escalation

Wed, 12 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Display And Peripheral Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-13T13:18:24.161Z

Reserved: 2026-07-07T17:04:34.467Z

Link: CVE-2026-59914

cve-icon Vulnrichment

Updated: 2026-08-13T13:18:18.481Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T20:17:46.407

Modified: 2026-08-17T20:19:32.693

Link: CVE-2026-59914

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T22:15:04Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-290

    Authentication Bypass by Spoofing