AI analysis
Dell System Update (DSU) versions before 2.3.0.0 contain an improper access control flaw (CWE-284) that lets a low-privileged user with local access on the server elevate their privileges, with some user interaction required (CVSS 3.1: 8.2, scope changed, high impact to confidentiality, integrity, and availability). Press coverage indicates the practical outcome is attackers gaining root-level code execution on the affected host, since DSU runs with high privileges to apply firmware and driver updates to Dell PowerEdge servers. The attack requires a foothold on the machine — such as a low-privileged service or user account — plus a social-engineering or lured-action component, so it is a post-compromise privilege escalation rather than a remote entry vector. Any organization running DSU on Linux or Windows server fleets with a version older than 2.3.0.0 is affected. There is no known public proof of concept and the flaw is not on the CISA KEV list, so exploitation activity appears limited at this time.
What to do: Upgrade Dell System Update to version 2.3.0.0 or later on every server where it is installed (check with 'dsu --version'), and remove or update stale DSU installations that admins may have left behind. Because exploitation needs local access plus user interaction, also restrict low-privileged local accounts on PowerEdge hosts and treat any unexpected privilege changes on servers running old DSU versions as suspicious.
Affected
| Dell System Update (DSU) | prior to 2.3.0.0 (< 2.3.0.0) |
Estimated exposure
large≈100,000–1,000,000 servers plausibly running a vulnerable DSU version (order of magnitude: 10^5) — DSU is Dell's standard update utility for its PowerEdge installed base (millions of servers shipped) and is commonly left installed on enterprise Linux/Windows server fleets, but exact install counts are not public, and many shops run it…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Dell System Update, versions prior to 2.3.0.0, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.