AI analysis
Dell System Update (DSU) versions prior to 2.3.0.0 contain an improper limitation of a pathname to a restricted directory (path traversal, CWE-22). A low-privileged attacker with local access, aided by some degree of user interaction, could abuse the flaw to escape restricted directories and achieve code execution with the elevated privileges DSU uses when applying firmware updates (press coverage of related DSU flaws describes root-level execution). Any organization running DSU on supported Dell systems (typically PowerEdge servers) with version 2.3.0.0 or earlier is affected. There is no public proof-of-concept and the issue is not in CISA's Known Exploited Vulnerabilities catalog, so exploitation status is none known; note that some headlines cite a different but similar DSU vulnerability (CVE-2026-86360) and should not be conflated with this one.
What to do: Upgrade Dell System Update to version 2.3.0.0 or later as soon as possible. In the interim, restrict which local accounts may run DSU and limit interactive/local logon rights on servers, since exploitation requires local access with low privileges and user interaction. Audit DSU installations and update logs for unexpected or manipulated update packages.
Affected
| Dell System Update (DSU) | prior to 2.3.0.0 (< 2.3.0.0) |
Estimated exposure
largeplausibly hundreds of thousands of servers (order of magnitude), not directly measurable — DSU is a locally installed firmware-update utility not visible in internet-wide scans, so the estimate rests on the multi-million-unit installed base of Dell PowerEdge servers of which DSU users are a substantial but unknown subset.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Remote execution.