Sceawere
Vulnerability Detail
CVE-2026-86361UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dell System Update Privilege Escalation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.2
- Creation Date
- 6h ago
- Vendor
- Dell
- Product
- System Update
- Attack Type
- CWE-732: Incorrect Permission Assignment for Critical Resource
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Dell System Update, versions prior to 2.3.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.2",
"pubDate": "2026-10-06T19:18:16.567Z",
"pubdate": "2026-10-06T19:18:16.567Z",
"executiveSummary": "Dell System Update (DSU), specifically versions prior to 2.3.0.0, is affected by an Incorrect Permission Assignment for Critical Resource vulnerability.\nThis flaw allows a local attacker with low-privileged access to escalate their system privileges.\nThe vulnerability originates from improper security configurations on resources critical to the update process, which an authenticated local user can abuse to gain higher-level permissions.\nSuccessful exploitation poses a significant security risk, as it permits unauthorized administrative access, potentially leading to full system compromise.\nThis issue does not require remote network access, as the threat vector is explicitly confined to local exploitation on the host system.",
"technicalDetails": "The vulnerability resides in Dell System Update (DSU) versions prior to 2.3.0.0, stemming from an Incorrect Permission Assignment for Critical Resource. This condition typically occurs when critical files, directories, or registry keys utilized by the application are assigned weak Access Control Lists (ACLs) during or after installation.\nIn a secure configuration, administrative utilities running with elevated privileges must ensure that their working directories, log files, and underlying binary dependencies are protected against unauthorized modification or tampering by non-privileged accounts.\nThe root cause of this vulnerability is the failure of the application installer or the service itself to enforce proper Principle of Least Privilege (PoLP) settings. By assigning overly permissive access rights (such as full modify or write access for non-admin users), the application allows a low-privileged local user to manipulate or replace these critical resources.\nThe exploitation flow begins with a local attacker identifying these insecurely permissioned resources. An attacker can leverage this access to perform a variety of actions, such as replacing a trusted binary or DLL with a malicious equivalent that the DSU service might execute during its next update cycle, or modifying configuration files to hijack the service's operational logic.\nBecause the DSU application operates with elevated system or administrative privileges, any malicious task injected via these compromised resources inherits the execution context of the vulnerable service.\nConsequently, the attacker effectively bridges the gap between their low-privileged user session and the high-privileged execution environment. Once the malicious payload or command is successfully executed within the context of the elevated service, the attacker gains unauthorized control, resulting in successful Elevation of Privilege.\nThis vulnerability is strictly local, meaning the attacker must already possess valid, albeit low-privileged, access to the target system. There is no requirement for network interaction, making this a classic vertical privilege escalation path."
}