CVE-2026-23772
7.3Dell · Storage Manager - Replay Manager for Microsoft Servers
Dell Storage Manager Replay Manager for Microsoft Servers version 8.0 is susceptible to an improper privilege management vulnerability, allowing local, low-privileged users to escalate their privileges.
Executive summary
A local privilege escalation vulnerability in Dell Storage Manager Replay Manager for Microsoft Servers poses a significant security risk by allowing low-privileged users to gain unauthorized administrative control.
Vulnerability
This flaw is classified as an improper privilege management vulnerability (CWE-269). It allows an attacker who has already obtained low-level local access to the system to escalate their privileges, effectively gaining higher control over the affected server environment.
Business impact
Successful exploitation of this vulnerability allows a local attacker to bypass standard security restrictions and gain elevated privileges on the host system. Given the CVSS score of 7.3, this represents a high-risk scenario where an attacker could potentially access sensitive data, modify system configurations, or cause service disruption, leading to significant operational and security compromise.
Remediation
Immediate Action: Upgrade Dell Storage Manager - Replay Manager for Microsoft Servers to version 8.0.3 or later as specified in the official Dell security advisory.
Proactive Monitoring: Audit system logs for unexpected privilege changes or suspicious local account activity originating from service-level accounts.
Compensating Controls: Restrict local access to the affected servers to only authorized personnel and implement strict least-privilege policies to limit the potential impact of local user account compromise.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability presents a clear path for privilege escalation within the server environment. Security teams should prioritize the application of the version 8.0.3 patch to eliminate the underlying weakness. Failure to remediate could allow an attacker with limited local access to gain full system control, necessitating urgent attention to this update.
More Dell CVEs
Sources
Originally found and disclosed by Dell would like to thank falconCorrup for reporting this issue., per the CVE Program record.