Impact
Dell Wyse Management Suite versions before 2605.0.2 contain an improper deserialization vulnerability that allows a low‑privileged attacker with local access to trigger privilege escalation. By feeding specially crafted data into the deserialization routine, the attacker can gain higher privileges on the host system.
Affected Systems
The affected product is Dell Wyse Management Suite (WMS) with all releases earlier than 2605.0.2. This includes any deployment of the suite where a non‑administrative user can execute code locally on a managed Windows device.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate severity, and the vulnerability is not listed in the CISA KEV catalog. The exploitation requires local access, so the risk is limited to environments where physical or local network access is possible. No public exploit has been reported, but the similarity to other improper deserialization flaws suggests that the attack vector could be expanded if an attacker gains initial local foothold.
OpenCVE Enrichment