DSA-2025-033: Security Update for Dell Display Manager for Multiple Vulnerabilities

Summary: Dell Display Manager remediation is available for multiple vulnerabilities that could be exploited by malicious users to compromise the affected system.

Acest articol se aplică pentru Acest articol nu se aplică pentru Acest articol nu este legat de un produs specific. Acest articol nu acoperă toate versiunile de produs existente.

Impact

Medium

Details

Proprietary Code CVEs

Description

CVSS Base Score

CVSS Vector String

CVE-2025-22394

Dell Display Manager, versions prior to 2.3.2.18, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to code execution and possibly privilege escalation.

6.7

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

CVE-2025-21101

Dell Display Manager, versions prior to 2.3.2.20, contain a race condition vulnerability.
A local malicious user could potentially exploit this vulnerability during installation, leading to arbitrary folder or file deletion.

6.6

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

Proprietary Code CVEs

Description

CVSS Base Score

CVSS Vector String

CVE-2025-22394

Dell Display Manager, versions prior to 2.3.2.18, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to code execution and possibly privilege escalation.

6.7

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

CVE-2025-21101

Dell Display Manager, versions prior to 2.3.2.20, contain a race condition vulnerability.
A local malicious user could potentially exploit this vulnerability during installation, leading to arbitrary folder or file deletion.

6.6

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Produse afectate și măsuri de remediere

CVE ID

Product

Software/Firmware

Affected Versions

Remediated Versions

Release Date

Link

CVE-2025-22394, CVE-2025-21101

Dell Display Manager

Software

Versions prior to 2.3.2.20

Versions 2.3.2.20 or later

01/08/2025

Support for Dell Display Manager 2.x | Drivers & Downloads

CVE ID

Product

Software/Firmware

Affected Versions

Remediated Versions

Release Date

Link

CVE-2025-22394, CVE-2025-21101

Dell Display Manager

Software

Versions prior to 2.3.2.20

Versions 2.3.2.20 or later

01/08/2025

Support for Dell Display Manager 2.x | Drivers & Downloads

Soluții alternative și strategii de atenuare

None

Revision History

Revision

Date

Description

1.0

2025-01-14

Initial Release

Acknowledgements

CVE-2025-21101: Dell Technologies would like to thank Ouallaout Noureddine for reporting this issue.

Related Information

Produse afectate

Dell Display Manager 2.x
Proprietăți articol
Article Number: 000267927
Article Type: Dell Security Advisory
Ultima modificare: 14 Jan 2025
Găsiți răspunsuri la întrebările dvs. de la alți utilizatori Dell
Servicii de asistență
Verificați dacă dispozitivul dvs. este acoperit de serviciile de asistență.