Executive brief
Dell Inventory Collector Client, a utility component used by multiple Dell system management products, contains an unquoted search path vulnerability that allows a low-privileged local attacker to execute arbitrary code with elevated privileges. An attacker with basic user access to an affected system could gain complete system compromise through privilege escalation and arbitrary code execution.
Technical details
The vulnerability is an unquoted search path flaw in the Inventory Collector Client prior to version 15.0.0. A low-privileged local attacker (PR:L) can exploit this without user interaction to achieve code execution and privilege escalation. The issue affects Dell Inventory Collector bundled within Dell SupportAssist, Dell Command | Update, Dell Optimizer, and Dell Trusted Device, all of which automatically update the vulnerable component.
Affected products
- Dell Inventory Collector Client prior to 15.0.0
- Dell SupportAssist for PCs (Home and Business)
- Dell Command | Update
- Dell Optimizer
- Dell Trusted Device
Timeline
- 2026-09-21: disclosed
- 2026-09-17: other: Initial advisory release