Impact
Dell Trusted Device Client versions before 8.1.359.0 contain a critical permission assignment flaw that allows a low‑privileged local attacker to tamper with protected data, including modifying or deleting sensitive information stored by the client. This can compromise the integrity of the system’s data.
Affected Systems
Dell Trusted Device Client, versions prior to 8.1.359.0.
Risk and Exploitability
The CVSS score of 7.1 denotes a high severity risk. The vulnerability requires local access, so exploitation is confined to systems where an attacker has local user credentials. Because no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, the likelihood of exploitation depends on the presence of local accounts. Nevertheless, a local attacker that can execute the flaw could tamper with critical client data.
OpenCVE Enrichment