Impact
Dell Wyse Management Suite (WMS) versions before 2605.0.2 contain an incorrect default permission that permits a low‑privileged local user to elevate their privileges, potentially granting full system control. The flaw is classified as CWE-269 and has a CVSS score of 7.8, indicating a high likelihood of a significant impact if exploited.
Affected Systems
The vulnerability applies to Dell Wyse Management Suite (WMS) installations running any version earlier than 2605.0.2. Local accounts that retain the default permissions are at risk.
Risk and Exploitability
The high CVSS score reflects serious risk, even though EPSS is not available and the vulnerability is not yet listed in the CISA KEV catalog. An attacker would need only local access with low privileges, making exploitation straightforward. Successful exploitation results in privilege escalation that can compromise the entire system.
OpenCVE Enrichment