Impact
Dell System Update versions prior to 2.3.0.0 contain a path traversal flaw (CWE-22) that permits a local attacker with low privileges to craft file references outside the intended Restricted Directory. If exploited, the attacker could execute arbitrary code on the host system, effectively achieving remote execution without elevated rights.
Affected Systems
Vendors: Dell. Product: System Update. All released builds earlier than version 2.3.0.0 are affected. No other sub‑versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 7.3 indicates high severity. While the EPSS score is not available, the vulnerability is not listed in the CISA KEV catalog. The attack is local, requiring the attacker to have logged on with low‑privilege credentials or access to the machine. Once executed, the attacker can gain code execution with the rights of the Service Update process, potentially leading to full system compromise.
OpenCVE Enrichment