CVE-2025-43884

8.2

Dell · PowerProtect Data Manager

Dell PowerProtect Data Manager versions 19.19 and 19.20 contain an OS command injection vulnerability in the Hyper-V component, allowing high-privileged local attackers to execute arbitrary commands.

Executive summary

A high-severity OS command injection vulnerability in Dell PowerProtect Data Manager could allow an authenticated attacker to achieve full system compromise.

Vulnerability

This is an improper neutralization of special elements used in an OS command (CWE-78) vulnerability. The flaw exists within the Hyper-V component and requires an attacker to possess high privileges and local access to the system to trigger command execution.

Business impact

The CVSS score of 8.2 reflects a high risk of total system compromise, including the potential for unauthorized data access, modification, or complete service disruption. Because this vulnerability grants command execution capabilities to an attacker, it poses a significant threat to the integrity and availability of protected backup data managed by the platform.

Remediation

Immediate Action: Upgrade to Dell PowerProtect Data Manager version 19.21 build 11 or later as specified in the vendor security advisory.

Proactive Monitoring: Review system access logs for unauthorized attempts to access Hyper-V management interfaces or unusual command-line executions originating from the Data Manager service account.

Compensating Controls: Restrict local access to the PowerProtect Data Manager server to only essential administrative personnel and implement strict least-privilege policies to limit the potential impact of a compromised account.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for complete system compromise through command injection, organizations should prioritize the deployment of the vendor-provided patch. Please verify your current version and apply the recommended update to version 19.21 build 11 immediately to mitigate this high-risk vulnerability.

More Dell CVEs

Sources