Executive brief
Dell Color Management is an application used to calibrate and manage color accuracy on Dell UltraSharp monitors. A security flaw in the software's installer allows a person with limited access to a computer to gain full administrative control. By tricking the installer into writing files to protected system areas, an attacker could disable security features or take over the entire operating system.
Technical details
A symbolic link (symlink) vulnerability exists in the Portrait Dell Color Management installer for Windows prior to version 3.7.0. During installation, the application writes a specific data file (CCFLFamily_07Feb11.edr) to a directory in C:\ProgramData\ with elevated privileges. Because the installer fails to validate whether the destination path contains symbolic links or reparse points, a local low-privileged attacker can create a malicious link at that location. This redirects the elevated write operation to an arbitrary system file, allowing the attacker to create or overwrite critical system files and achieve local privilege escalation (LPE) to Administrator. The issue is resolved in version 3.7.0.0 and higher.
Affected products
- Dell Color Management before 3.7.0
Timeline
- 2026-05-19: disclosed
- 2026-05-19: advisory