Impact
The vulnerability in Dell Display and Peripheral Manager (DDPM) Windows arises from an improper access control flaw, allowing a low‑privileged local attacker to execute commands with higher privileges. This weakness can lead to elevation of privileges and arbitrary code execution on the affected system. The flaw is identified as CWE‑290, highlighting a lack of proper access enforcement.
Affected Systems
The affected product is Dell Display and Peripheral Manager (DDPM) for Windows, with all versions earlier than 2.3.0.17. The vulnerability remains in any pre‑2.3.0.17 installation and impacts all users with local access.
Risk and Exploitability
The CVSS score of 7.8 indicates a moderate to high severity, yet the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is local and requires a low privileged user, suggesting that exploitation would need presence on the device or other local means. Nonetheless, the potential for privilege escalation and arbitrary code execution warrants immediate attention.
OpenCVE Enrichment