Executive brief
Dell Display and Peripheral Manager is a Windows application used to manage monitor settings and peripheral devices. A security flaw in this software could allow a person with low-level access to a computer to run unauthorized commands with higher privileges. This could lead to a full system compromise, allowing an attacker to access sensitive data or disrupt operations.
Technical details
An improper access control vulnerability (CWE-284) exists in Dell Display and Peripheral Manager (DDPM) for Windows in versions prior to 2.3. The flaw allows a low-privileged attacker with local access to the host operating system to exploit weak permissions or access controls within the application. Successful exploitation can lead to arbitrary code execution in the context of the application or system. Dell has released version 2.3 to remediate this issue.
Affected products
- Dell Display and Peripheral Manager (DDPM Windows) prior to 2.3
Timeline
- 2026-06-16: advisory: Initial release of Dell Security Advisory DSA-2026-277
- 2026-06-25: disclosed: NVD publication date