CVE-2026-71180
massLocal Privilege Escalation via Unchecked Return Value in Dell Update Package Framework
Dell Update Package Framework versions prior to 26.07.03 fail to verify a return value before proceeding (CWE-252, Unchecked Return Value), a flaw that a low-privileged local attacker can leverage to gain elevated privileges on the host. The attack requires local access to the machine and user interaction (per the CVSS UI:R metric), consistent with inducing a privileged update process to continue past a failed operation. Because the CVSS scope is changed with high confidentiality, integrity, and availability impact, a successful exploit can compromise resources beyond the vulnerable component's security context. Any Dell client system or administrator workstation running the framework below the fixed version is affected. No public proof-of-concept and no known in-the-wild exploitation have been reported, and the issue is not on the CISA KEV catalog.
What to do: Update Dell Update Package Framework to version 26.07.03 or later, obtainable through Dell Command | Update, Dell Update, or the Dell support site, and verify the installed version in the Windows apps list or via the Dell utility. Because exploitation requires local access, prioritize patching shared or multi-user endpoints and remind users not to run untrusted local code while unpatched.
| Dell Update Package Framework | all versions prior to 26.07.03 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
- Weakness
- CWE-252
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.