DSA-2026-417: Security update for Dell Update Package (DUP) Framework Vulnerabilities

Oversigt: Dell Update Package (DUP) Framework remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

Denne artikel gælder for Denne artikel gælder ikke for Denne artikel er ikke knyttet til et bestemt produkt. Det er ikke alle produktversioner, der er identificeret i denne artikel.

Virkning

High

Oplysninger

Proprietary Code CVEs

Description

CVSS Base Score

CVSS Vector String

CVE-2026-71179

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

7.3

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

CVE-2026-71180

Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

8.2

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

CVE-2026-71181

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.

3.0

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:LThis hyperlink is taking you to a website outside of Dell Technologies.

CVE-2026-71182

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.

3.0

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:LThis hyperlink is taking you to a website outside of Dell Technologies.

CVE-2026-86358

Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote execution.

6.5

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

 

Proprietary Code CVEs

Description

CVSS Base Score

CVSS Vector String

CVE-2026-71179

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

7.3

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

CVE-2026-71180

Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

8.2

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

CVE-2026-71181

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.

3.0

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:LThis hyperlink is taking you to a website outside of Dell Technologies.

CVE-2026-71182

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.

3.0

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:LThis hyperlink is taking you to a website outside of Dell Technologies.

CVE-2026-86358

Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote execution.

6.5

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

 

Dell Technologies anbefaler, at alle kunder tager hensyn til både CVSS-basisresultatet og alle relevante tidsmæssige og miljømæssige resultater, som kan have betydning for den potentielle alvorsgrad, der er forbundet med en bestemt sikkerhedsrisiko.

Berørte produkter og udbedring

Product

Affected Versions

Remediated Versions

Link

Dell Update Package (DUP) Framework

Version prior to 26.07.03

Version 26.07.03 or later

https://www.dell.com/support

 

Product

Affected Versions

Remediated Versions

Link

Dell Update Package (DUP) Framework

Version prior to 26.07.03

Version 26.07.03 or later

https://www.dell.com/support

 

Note: To check the DUP Framework file version, right-click on the DUP file, select Properties, and click on the Details tab to find the File version number.

Revisionshistorik

Revision

Date

Description

1.0

2026-09-15

Initial Release

 

Relaterede oplysninger

Berørte produkter

Dell Update Packages - Current Version
Artikelegenskaber
Artikelnummer: 000509455
Artikeltype: Dell Security Advisory
Senest ændret: 15 sep. 2026
Find svar på dine spørgsmål fra andre Dell-brugere
Supportservices
Kontrollér, om din enhed er dækket af supportservices.