Impact
The Dell Update Package Framework contains an Improper Link Resolution Before File Access vulnerability (CWE‑59). A local attacker with high privileges could manipulate the framework to resolve arbitrary links and then access or read files that the framework process can reach. This could result in unintended disclosure of system files or configuration data, compromising confidentiality of sensitive files.
Affected Systems
Versions of the framework released before 26.07.03 are affected. The vendor, Dell, identifies this as a Update Package Framework update package. Systems running these earlier versions should be reviewed to confirm compliance.
Risk and Exploitability
The CVSS score of 3 indicates low severity overall, and the EPSS score of less than 1% shows a low likelihood of exploitation in the wild. The vulnerability is not currently marked in the CISA KEV catalog. Exploitation requires local access and high privileges, limiting the attack surface to compromised accounts or physical access. If a local privilege escalation has already occurred, this flaw provides a straightforward path to read arbitrary files in the system.
OpenCVE Enrichment