CVE-2025-46691

7.8

Dell · PremierColor Panel Driver

A local privilege escalation vulnerability exists in the Dell PremierColor Panel Driver due to improper access control.

Executive summary

A local privilege escalation vulnerability in the Dell PremierColor Panel Driver allows a low privileged attacker to potentially gain elevated system access.

Vulnerability

This vulnerability involves improper access control (CWE-284) within the driver, which allows a local attacker with low privileges to achieve elevation of privileges on the affected system.

Business impact

Successful exploitation of this vulnerability could allow a malicious actor to bypass standard security restrictions, potentially gaining full control over the affected workstation. Given the CVSS score of 7.8, this poses a significant risk to organizational integrity, as it facilitates the escalation of local access to administrative or system-level capabilities, which could lead to data exfiltration or the deployment of persistent malware.

Remediation

Immediate Action: Update the Dell PremierColor Panel Driver to version 1.0.0.1 A01 or later as specified in the official Dell security advisory.

Proactive Monitoring: Review system logs for unusual process execution or unauthorized attempts to access protected system directories.

Compensating Controls: Ensure that workstation users are restricted to the minimum necessary privilege levels, as local access is a prerequisite for this exploit.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The risk associated with this local privilege escalation vulnerability is high, particularly in multi-user environments where standard users could potentially compromise system integrity. IT administrators should prioritize the deployment of the vendor-provided driver update across all affected Dell systems to effectively neutralize the risk of unauthorized privilege escalation.

More Dell CVEs

Sources