8.2
CVE-2026-23857
- EPSS 0.01%
- Veröffentlicht 12.02.2026 02:05:31
- Zuletzt bearbeitet 18.02.2026 19:33:06
- Quelle security_alert@emc.com
- CVE-Watchlists
- Unerledigt
Dell Update Package (DUP) Framework, versions 23.12.00 through 24.12.00, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Update Package Framework Version >= 23.12.00 < 25.02.00
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.01% | 0.014 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security_alert@emc.com | 8.2 | 1.5 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
|
CWE-280 Improper Handling of Insufficient Permissions or Privileges
The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.