DSA-2026-081: Security Update for Dell Update Package (DUP) Framework vulnerability
Zusammenfassung: Dell Update Package (DUP) Framework remediation is available for Improper Handling of Insufficient Permissions or Privileges vulnerability that could be exploited by malicious users to compromise the affected system. ...
Auswirkungen
High
Details
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-23857 |
Dell Update Package (DUP) Framework, versions 23.12.00 through 24.12.00, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
8.2 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-23857 |
Dell Update Package (DUP) Framework, versions 23.12.00 through 24.12.00, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
8.2 |
Betroffene Produkte und Korrektur
|
Product |
Affected Versions |
Remediated Versions |
Link |
|
Dell Update Package (DUP) Framework |
Versions 23.12.00 through 24.12.00 |
Version 25.02.00 |
|
Product |
Affected Versions |
Remediated Versions |
Link |
|
Dell Update Package (DUP) Framework |
Versions 23.12.00 through 24.12.00 |
Version 25.02.00 |
No action required from the customer if Dell Update Package (DUP) Framework v25.02.00 is used to update Driver/Firmware using DUP. However, we recommend following the workaround mentioned below.
Workarounds und Korrekturmaßnahmen
|
CVE ID |
Workaround and Mitigation |
|
CVE-2026-23857 |
Recommend users to use Dell Update Package (DUP) built with Framework v25.02.00 onwards to update Driver/Firmware using DUP. |
Revisionsverlauf
|
Revision |
Date |
Description |
|
1.0 |
2026-02-11 |
Initial Release |
Danksagung
Dell would like to thank Gee-netics for reporting this issue.