Impact
The Dell Display and Peripheral Manager (DDPM) Windows software contains an authentication bypass vulnerability that permits a spoofed credential attack. The flaw can be leveraged by a low‑privileged local user to elevate privileges and execute arbitrary code. This constitutes an authorization weakness (CWE‑284, CWE‑290) and can lead to system‑level compromise.
Affected Systems
Dell Display and Peripheral Manager (DDPM) Windows versions prior to 2.3.0.17 are affected. All editions under the Dell:Display and Peripheral Manager (DDPM Windows) vendor designation are vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of 0.00129 (about 0.13%) indicates a very low but nonzero exploitation probability. The vulnerability is not listed in CISA KEV. The attack vector is local and requires a low‑privileged user. The CVE description does not cite a publicly available exploit, but the flaw still enables local privilege escalation and arbitrary code execution, posing a significant risk to affected systems.
OpenCVE Enrichment