DSA-2026-295: Security Update for Dell Monitor Driver for an Improper Link Resolution Before File Access ('Link Following') Vulnerability
Summary: Dell Monitor driver remediation is available for an Improper Link Resolution Before File Access ('Link Following’) vulnerability that could be exploited by malicious users to compromise the affected system. ...
Impact
Medium
Additional Details
This issue occurs only during the installation of Dell Monitor drivers mentioned in the Affected Products and Remediation table. If you already have Dell Monitor driver version prior to 1.0.0.0, installed, you do not need to reinstall, as the vulnerability exists in the installer process only—not the installed driver.
Details
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-40717 |
Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. |
6.6 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-40717 |
Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. |
6.6 |
Affected Products & Remediation
Revision History
"
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2026-08-03 | Initial Release |
Acknowledgements
Dell Technologies would like to thank falconCorrup for reporting this issue.