Impact
Dell System Update contains an Incorrect Permission Assignment for Critical Resource vulnerability that allows a low‑privileged local attacker to gain elevated privileges. The flaw arises when critical system files are assigned permissions that unintentionally grant broader access to non‑administrative users, enabling the attacker to modify or execute privileged operations. This weakness is identified as CWE‑732 and results in potential unauthorized escalation of privileges within the affected system.
Affected Systems
The affected product is Dell System Update, specifically all releases prior to version 2.3.0.0. Systems running any such earlier build are vulnerable regardless of the underlying operating system. Administrators should verify the installed version and plan a patch if a vulnerable build is in use.
Risk and Exploitability
With a CVSS score of 8.2, the vulnerability is considered high severity, though its EPSS score is not available. It is not currently listed in the CISA KEV catalog. The attack vector is local, requiring an attacker to have low‑privileged access on the same machine. Once exploited, the attacker can elevate privileges and potentially perform arbitrary actions with elevated rights. Prompt remediation is recommended.
OpenCVE Enrichment