DSA-2025-033: Security Update for Dell Display Manager for Multiple Vulnerabilities
Summary: Dell Display Manager remediation is available for multiple vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impact
Medium
Details
| Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
| CVE-2025-22394 |
Dell Display Manager, versions prior to 2.3.2.18, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to code execution and possibly privilege escalation. |
6.7 |
|
| CVE-2025-21101 |
Dell Display Manager, versions prior to 2.3.2.20, contain a race condition vulnerability. |
6.6 |
| Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
| CVE-2025-22394 |
Dell Display Manager, versions prior to 2.3.2.18, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to code execution and possibly privilege escalation. |
6.7 |
|
| CVE-2025-21101 |
Dell Display Manager, versions prior to 2.3.2.20, contain a race condition vulnerability. |
6.6 |
Affected Products & Remediation
| CVE ID |
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Release Date |
Link |
| CVE-2025-22394, CVE-2025-21101 |
Dell Display Manager |
Software |
Versions prior to 2.3.2.20 |
Versions 2.3.2.20 or later |
01/08/2025 |
| CVE ID |
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Release Date |
Link |
| CVE-2025-22394, CVE-2025-21101 |
Dell Display Manager |
Software |
Versions prior to 2.3.2.20 |
Versions 2.3.2.20 or later |
01/08/2025 |
Workarounds & Mitigations
None
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2025-01-14 |
Initial Release |
Acknowledgements
CVE-2025-21101: Dell Technologies would like to thank Ouallaout Noureddine for reporting this issue.