Description
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.
Published: 2026-08-12
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Display and Peripheral Manager (DDPM) for Windows versions before 2.3.0.17 contains an Improper Access Control flaw. A local attacker with low privileges can bypass security checks to gain higher level rights, which may allow the attacker to run arbitrary code on the affected system.

Affected Systems

The vulnerability affects Dell DDPM Windows versions prior to 2.3.0.17. No specific service or subsystem variations are listed beyond the overall product; systems running any of these older DDPM releases are susceptible.

Risk and Exploitability

The CVSS base score of 7.8 indicates high severity, and while an EPSS score is not provided, the lack of a KEV listing suggests no current widespread exploitation but the potential for local actors to leverage the flaw remains substantial. The likely attack vector is local with low privileges; a user who can log on locally could exploit the improper access control to elevate privileges and execute code.

Generated by OpenCVE AI on August 12, 2026 at 23:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Dell security update for DDPM Windows covering version 2.3.0.17 or later as released through Dell’s support site.
  • If an update cannot be applied immediately, uninstall DDPM Windows to eliminate the vulnerable component.
  • Implement least privilege for local accounts and restrict physical access to prevent local attackers from exploiting the vulnerability.

Generated by OpenCVE AI on August 12, 2026 at 23:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:display_and_peripheral_manager:*:*:*:*:*:windows:*:*

Thu, 13 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell display And Peripheral Manager
Vendors & Products Dell
Dell display And Peripheral Manager

Wed, 12 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Dell Display and Peripheral Manager Windows Allows Local Privilege Escalation

Wed, 12 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Display And Peripheral Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-13T13:18:09.325Z

Reserved: 2026-07-07T17:04:34.467Z

Link: CVE-2026-59917

cve-icon Vulnrichment

Updated: 2026-08-13T13:18:02.636Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T20:17:46.663

Modified: 2026-08-17T20:17:28.363

Link: CVE-2026-59917

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:15:07Z

Weaknesses