Description
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Improper Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
Published: 2026-08-14
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Wyse Management Suite versions before 2605.0.2 contain an improper deserialization vulnerability that allows a low‑privileged attacker with local access to trigger privilege escalation. By feeding specially crafted data into the deserialization routine, the attacker can gain higher privileges on the host system.

Affected Systems

The affected product is Dell Wyse Management Suite (WMS) with all releases earlier than 2605.0.2. This includes any deployment of the suite where a non‑administrative user can execute code locally on a managed Windows device.

Risk and Exploitability

The CVSS score of 6.3 indicates a moderate severity, and the vulnerability is not listed in the CISA KEV catalog. The exploitation requires local access, so the risk is limited to environments where physical or local network access is possible. No public exploit has been reported, but the similarity to other improper deserialization flaws suggests that the attack vector could be expanded if an attacker gains initial local foothold.

Generated by OpenCVE AI on August 14, 2026 at 16:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell Wyse Management Suite 2605.0.2 update or a later version that contains the fix for the improper deserialization flaw
  • Ensure that local user accounts are assigned only the minimum privileges required for their role and enforce strong password policies
  • Revoke any unnecessary local access permissions and monitor for unexpected privilege changes on managed devices

Generated by OpenCVE AI on August 14, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Improper Deserialization Leading to Local Privilege Escalation in Dell Wyse Management Suite

Fri, 14 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Improper Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-14T16:13:27.150Z

Reserved: 2026-07-17T17:05:09.171Z

Link: CVE-2026-63701

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T16:16:58.683

Modified: 2026-08-14T16:16:58.683

Link: CVE-2026-63701

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T16:30:05Z

Weaknesses
  • CWE-269

    Improper Privilege Management