Impact
The vulnerability resides in the Dell Update Package Framework before version 26.07.03. An unchecked return value allows a local user with low privileges to trigger context‑dependent actions that ultimately raise privileges. This weakness maps to CWE‑252 and can result in unauthorized system access and data tampering.
Affected Systems
All Dell hosts that run the Update Package Framework earlier than 26.07.03 are affected. The flaw applies to the component distributed by Dell, so any Dell machine that relies on this framework before the specified release is likely impacted.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity, while the EPSS score under 1% signals a low probability of exploitation. The vulnerability is not currently listed in the CISA KEV catalog. Because the flaw requires local access, an attacker must be able to log on or maintain a local session, but exploitation can lead to privilege escalation and potentially full administrative control over the system.
OpenCVE Enrichment