AI analysis
Dell System Update (DSU) prior to version 2.3.0.0 suffers from an Incorrect Permission Assignment for Critical Resource flaw (CWE-732), meaning a file, directory, or other resource used by the privileged DSU component is writable or controllable by lower-privileged users. A local attacker with an existing low-privileged account and some user interaction (per the CVSS vector AV:L/AC:L/PR:L/UI:R) can hijack that misassigned resource to escalate privileges, with the scope-change flag indicating impact beyond DSU itself — news coverage reports attackers can gain root and execute code as the root user on the host. This affects Dell servers (typically PowerEdge Linux systems) running an outdated DSU build. Exploitation requires local access, so it is primarily a risk on multi-user servers, jump hosts, or machines where attackers already have a foothold. There is no known public PoC, the flaw is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported; note that coverage also references a companion flaw, CVE-2026-86360, in the same advisory.
What to do: Upgrade Dell System Update to version 2.3.0.0 or later (check installed version with 'dsu --version' or via OpenManage) and review Dell's security advisory, which also covers the related CVE-2026-86360. Until patched, restrict who holds local accounts on PowerEdge hosts, audit existing low-privileged users, and monitor for suspicious DSU-related service or binary executions.
Affected
| Dell System Update (DSU) | prior to 2.3.0.0 (all versions before 2.3.0.0) |
Estimated exposure
large≈tens of thousands of servers (rough order-of-magnitude; no public install counts) — likely low real-world exposure since local access is required — Dell is the largest x86 server vendor and DSU is a widely used firmware/driver update utility on PowerEdge Linux fleets, but DSU is a locally installed admin tool (not internet-exposed) and no public install counts or scan data exist, so…
Description
Dell System Update, versions prior to 2.3.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.