Executive brief
Dell Peripheral Manager is a software utility used to customize and manage Dell accessories like keyboards and mice. A security flaw in this software could allow a local attacker to run unauthorized programs on a user's computer by tricking the application into loading a malicious file. If successful, this could lead to a full system compromise, though it requires the attacker to already have limited access to the machine and for a user to perform a specific action.
Technical details
Dell Peripheral Manager versions prior to 1.7.3 are vulnerable to an uncontrolled search path element vulnerability (CWE-427). The application fails to properly validate or restrict the paths used to search for external library files (DLLs). A local attacker with low privileges can exploit this by placing a malicious DLL in a directory searched by the application. When a user runs the software, the malicious code is executed with the privileges of the application. This attack requires local access, high complexity due to specific timing or placement requirements, and user interaction. Dell has released version 1.7.3 to remediate this issue.
Affected products
- Dell Peripheral Manager prior to 1.7.3
Timeline
- 2024-03-27: patched: Remediated version 1.7.3 released
- 2024-04-02: advisory: Initial advisory published by Dell
- 2026-06-16: disclosed: NVD publication date