Junglewise Threat Intelligence

CVE-2026-44275: Dell Alienware Purchased Apps arbitrary file write via link following

CVE-2026-44275 · Severity: medium · CVSS 6.3 · Published 2026-06-09

Vendors: Dell.

Executive brief

Dell and Alienware Purchased Apps contain a security flaw that could allow a user with limited access to modify system files. This application is used to manage software purchased through Dell on consumer and business PCs. If exploited, an attacker could potentially gain higher privileges or cause system instability by overwriting critical files.

Technical details

Dell/Alienware Purchased Apps versions prior to 1.1.32.0 are vulnerable to an Improper Link Resolution Before File Access (CWE-59), also known as a link following or symlink race vulnerability. A low-privileged local attacker can exploit this by creating symbolic links or junctions that point to sensitive system files. When the application attempts to write to a file at the expected location, it follows the link and instead writes to the attacker's target. This results in an arbitrary file write, which can be leveraged for privilege escalation or denial of service. The vulnerability is mitigated by a high attack complexity (AC:H), likely due to timing requirements or specific file system conditions. A patch is available in version 1.1.32.0.

Affected products

  • Dell Purchased Apps prior to 1.1.32.0
  • Alienware Purchased Apps prior to 1.1.32.0

Timeline

  • 2026-06-04: patched: Remediated version 1.1.32.0 released.
  • 2026-06-08: advisory: Initial Dell security advisory (DSA-2026-250) published.
  • 2026-06-09: disclosed: CVE published to NVD.

References