ZeroHour

CVE-2026-71180

mass

Local Privilege Escalation via Unchecked Return Value in Dell Update Package Framework

CVSS 3.1
8.2 high
EPSS
Published
()
Modified
AI analysis

Dell Update Package Framework versions prior to 26.07.03 fail to verify a return value before proceeding (CWE-252, Unchecked Return Value), a flaw that a low-privileged local attacker can leverage to gain elevated privileges on the host. The attack requires local access to the machine and user interaction (per the CVSS UI:R metric), consistent with inducing a privileged update process to continue past a failed operation. Because the CVSS scope is changed with high confidentiality, integrity, and availability impact, a successful exploit can compromise resources beyond the vulnerable component's security context. Any Dell client system or administrator workstation running the framework below the fixed version is affected. No public proof-of-concept and no known in-the-wild exploitation have been reported, and the issue is not on the CISA KEV catalog.

What to do: Update Dell Update Package Framework to version 26.07.03 or later, obtainable through Dell Command | Update, Dell Update, or the Dell support site, and verify the installed version in the Windows apps list or via the Dell utility. Because exploitation requires local access, prioritize patching shared or multi-user endpoints and remind users not to run untrusted local code while unpatched.

Affected
Dell Update Package Frameworkall versions prior to 26.07.03
Estimated exposure
masslikely millions of Dell client PCs (framework ships with preinstalled Dell Update / Dell Command | Update components on Dell Latitude, OptiPlex, Precision, XPS… — Dell's update components are preinstalled on the tens of millions of Dell client PCs shipped annually, so the population of endpoints with the framework is plausibly in the millions, though the number actually running a vulnerable version…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

Weakness
CWE-252
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.