Impact
The vulnerability in Dell Update Package Framework is an OS Command Injection flaw that allows a low‑privileged local user to execute arbitrary operating system commands. By exploiting this flaw, an attacker can elevate their privileges, potentially gaining full system control. The weakness corresponds to CWE‑78.
Affected Systems
Dell Update Package Framework versions older than 26.07.03 are affected. The vulnerability applies to all installations of the framework using these legacy releases.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity, while the EPSS score of less than 1% suggests only a very low probability of widespread exploitation at this time. The flaw is not listed in the CISA KEV catalog, but it can be exploited locally by any user who has basic access to the system. The attack vector is local and requires no network connectivity, making it important for environments where users have unrestricted local access.
OpenCVE Enrichment