7.8

CVE-2026-40717

Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Monitor Driver Version 1.0.0.0
   Dell ≫ Aw2526hl Version -
   Dell ≫ Aw2725dm Version -
   Dell ≫ Aw2726dl Version -
   Dell ≫ Aw2726dm Version -
   Dell ≫ Aw3225dm Version -
   Dell ≫ Aw3425dwm Version -
   Dell ≫ E2722h Version -
   Dell ≫ E2722hs Version -
   Dell ≫ E2723h Version -
   Dell ≫ E2723hn Version -
   Dell ≫ E2724hs Version -
   Dell ≫ E2725h Version -
   Dell ≫ E2725hm Version -
   Dell ≫ G2724d Version -
   Dell ≫ P1917s Version -
   Dell ≫ P2421d Version -
   Dell ≫ P2421dc Version -
   Dell ≫ P2425d Version -
   Dell ≫ P2425de Version -
   Dell ≫ P2720d Version -
   Dell ≫ P2720dc Version -
   Dell ≫ P2723d Version -
   Dell ≫ P2723de Version -
   Dell ≫ P5524q Version -
   Dell ≫ S2725ds Version -
   Dell ≫ S2725dsm Version -
   Dell ≫ S3221qs Version -
   Dell ≫ S3222dgm Version -
   Dell ≫ S3222hg Version -
   Dell ≫ S3222hn Version -
   Dell ≫ S3222hs Version -
   Dell ≫ S3225qc Version -
   Dell ≫ S3225qs Version -
   Dell ≫ S3422dwg Version -
   Dell ≫ S3425dw Version -
   Dell ≫ Se2423ds Version -
   Dell ≫ Se2426hg Version -
   Dell ≫ Se2426hgs Version -
   Dell ≫ Se2722h Version -
   Dell ≫ Se2722hr Version -
   Dell ≫ Se2722hx Version -
   Dell ≫ Se2723ds Version -
   Dell ≫ Se2725h Version -
   Dell ≫ Se2725hm Version -
   Dell ≫ Se2726d Version -
   Dell ≫ Se2726h Version -
   Dell ≫ Se2726hs Version -
   Dell ≫ Se3223q Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.018
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EMC 6.6 1.3 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

https://www.dell.com/support/kbdoc/en-us/000481265/dsa-2026-295
Vendor Advisory