Executive brief
Dell Peripheral Manager is a software application used to customize and manage Dell accessories like keyboards and mice. A security flaw in certain versions could allow a person with local access to the computer to run unauthorized programs by tricking the software into loading a malicious file. If successful, this could allow an attacker to take full control of the affected system, potentially leading to data theft or service disruption.
Technical details
Dell Peripheral Manager (versions 1.5.1 through 1.7.2) is vulnerable to an uncontrolled search path element (CWE-427) flaw. The application fails to properly validate or restrict the paths used to search for required executables, allowing a local attacker to place a malicious executable in a location searched by the application. Exploitation requires local access, low privileges, and high complexity (likely involving specific timing or user interaction), but can result in full compromise of confidentiality, integrity, and availability. Dell has released version 1.7.3 to remediate this issue.
Affected products
- Dell Peripheral Manager 1.5.1 to 1.7.2
Timeline
- 2024-03-27: patched: Remediated version 1.7.3 released
- 2024-04-02: advisory: Initial Dell security advisory (DSA-2024-055) published
- 2026-06-16: disclosed: NVD publication date