Description
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.
Published: 2026-08-12
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Dell Display and Peripheral Manager (DDPM) Windows arises from an improper access control flaw, allowing a low‑privileged local attacker to execute commands with higher privileges. This weakness can lead to elevation of privileges and arbitrary code execution on the affected system. The flaw is identified as CWE‑290, highlighting a lack of proper access enforcement.

Affected Systems

The affected product is Dell Display and Peripheral Manager (DDPM) for Windows, with all versions earlier than 2.3.0.17. The vulnerability remains in any pre‑2.3.0.17 installation and impacts all users with local access.

Risk and Exploitability

The CVSS score of 7.8 indicates a moderate to high severity, yet the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is local and requires a low privileged user, suggesting that exploitation would need presence on the device or other local means. Nonetheless, the potential for privilege escalation and arbitrary code execution warrants immediate attention.

Generated by OpenCVE AI on August 12, 2026 at 22:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Dell security update DSA‑2026‑320 for DDPM Windows, which addresses the improper access control flaw.
  • Upgrade DDPM Windows to version 2.3.0.17 or later to ensure the vulnerability is fixed.
  • Enforce the principle of least privilege for all users running DDPM, limiting local access to administrative functions.

Generated by OpenCVE AI on August 12, 2026 at 22:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:display_and_peripheral_manager:*:*:*:*:*:windows:*:*

Thu, 13 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell display And Peripheral Manager
Vendors & Products Dell
Dell display And Peripheral Manager

Wed, 12 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Dell Display and Peripheral Manager (DDPM Windows)

Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Display And Peripheral Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-13T13:20:08.210Z

Reserved: 2026-07-07T17:04:34.467Z

Link: CVE-2026-59916

cve-icon Vulnrichment

Updated: 2026-08-13T13:20:00.547Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T20:17:46.547

Modified: 2026-08-17T20:18:22.887

Link: CVE-2026-59916

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:15:07Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing