Impact
An improper access control flaw exists in Dell System Update, allowing a local attacker with low privileges to exploit the vulnerability. By bypassing normal authorization checks, the attacker can gain higher level privileges on the affected system. The flaw is categorized as CWE-284, reflecting unauthorized access to privileged resources.
Affected Systems
Dell System Update versions earlier than 2.3.0.0 are affected. All installations of the Dell System Update client that have not been upgraded to 2.3.0.0 or later remain vulnerable.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity risk. The EPSS score is not available, so the exact exploitation likelihood cannot be quantified, but the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local, requiring an attacker to have physical or local administrative access to the host. Once the privilege escalation is achieved, the attacker could install malicious software, access sensitive data, or further compromise the system.
OpenCVE Enrichment