DSA-2026-081: Security Update for Dell Update Package (DUP) Framework vulnerability
Podsumowanie: Dell Update Package (DUP) Framework remediation is available for Improper Handling of Insufficient Permissions or Privileges vulnerability that could be exploited by malicious users to compromise the affected system. ...
Skutki
High
Szczegóły
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-23857 |
Dell Update Package (DUP) Framework, versions 23.12.00 through 24.12.00, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
8.2 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-23857 |
Dell Update Package (DUP) Framework, versions 23.12.00 through 24.12.00, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
8.2 |
Produkty, których dotyczy problem, i środki zaradcze
|
Product |
Affected Versions |
Remediated Versions |
Link |
|
Dell Update Package (DUP) Framework |
Versions 23.12.00 through 24.12.00 |
Version 25.02.00 |
|
Product |
Affected Versions |
Remediated Versions |
Link |
|
Dell Update Package (DUP) Framework |
Versions 23.12.00 through 24.12.00 |
Version 25.02.00 |
No action required from the customer if Dell Update Package (DUP) Framework v25.02.00 is used to update Driver/Firmware using DUP. However, we recommend following the workaround mentioned below.
Obejścia problemu i środki zaradcze
|
CVE ID |
Workaround and Mitigation |
|
CVE-2026-23857 |
Recommend users to use Dell Update Package (DUP) built with Framework v25.02.00 onwards to update Driver/Firmware using DUP. |
Historia zmian
|
Revision |
Date |
Description |
|
1.0 |
2026-02-11 |
Initial Release |
Podziękowania
Dell would like to thank Gee-netics for reporting this issue.