« Back to list

Dell

Dell Command Update: vulnerabilities and CVEs

Dell Command Update has 22 published vulnerabilities, 11 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs22
Last 12 months11
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-67268Medium (6.5)0.15%—Aug 19, 2026
Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this…
CVE-2026-67267Medium (5.5)0.15%—Aug 19, 2026
Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker with local access could potentially…
CVE-2026-67266Medium (5.5)0.12%—Aug 19, 2026
Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of…
CVE-2026-58565High (8.8)0.14%—Aug 19, 2026
Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of…
CVE-2026-58564High (7.8)0.14%—Aug 19, 2026
Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem…
CVE-2026-58562High (7.3)0.14%—Aug 19, 2026
Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
CVE-2026-56797High (7.3)0.12%—Aug 19, 2026
Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to…
CVE-2026-56796Medium (6.6)0.17%—Aug 19, 2026
Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this…
CVE-2026-53477High (7.8)0.12%—Aug 19, 2026
Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability,…
CVE-2026-49817High (7.8)0.31%—Aug 19, 2026
Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to…
CVE-2026-49816High (7.8)0.31%—Aug 19, 2026
Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to…
CVE-2024-28962High (7.5)0.38%—Aug 6, 2024
Dell Command | Update, Dell Update, and Alienware Update UWP, versions prior to 5.4, contain an Exposed Dangerous Method or Function vulnerability. An unauthenticated attacker with remote access could potentially…
CVE-2023-28065High (7.3)0.19%—Jun 23, 2023
Dell Command | Update, Dell Update, and Alienware Update versions 4.8.0 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this…
CVE-2023-28071High (7.1)0.18%—Jun 23, 2023
Dell Command | Update, Dell Update, and Alienware Update versions 4.9.0, A01 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this…
CVE-2022-34384High (7.8)0.23%—Feb 11, 2023
Dell SupportAssist Client Consumer (version 3.11.1 and prior), SupportAssist Client Commercial (version 3.2 and prior), Dell Command | Update, Dell Update, and Alienware Update versions before 4.5 contain a Local…
CVE-2023-23698High (7.1)0.18%—Feb 10, 2023
Dell Command | Update, Dell Update, and Alienware Update versions before 4.6.0 and 4.7.1 contain Insecure Operation on Windows Junction in the installer component. A local malicious user may potentially exploit this…
CVE-2022-34459High (7.8)0.15%—Feb 1, 2023
Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a improper verification of cryptographic signature in get applicable driver component. A local malicious user could potentially…
CVE-2022-34458Medium (5.5)0.18%—Feb 1, 2023
Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in download operation component. A local…
CVE-2022-34382High (7.8)0.19%—Sep 2, 2022
Dell Command Update, Dell Update and Alienware Update versions prior to 4.6.0 contains a Local Privilege Escalation Vulnerability in the custom catalog configuration. A local malicious user may potentially exploit this…
CVE-2022-24426High (7.8)0.24%—Apr 1, 2022
Dell Command | Update, Dell Update, and Alienware Update version 4.4.0 contains a Local Privilege Escalation Vulnerability in the Advanced Driver Restore component. A local malicious user could potentially exploit this…
CVE-2019-3750Medium (5.5)0.32%—Dec 3, 2019
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files…
CVE-2019-3749Medium (5.5)0.32%—Dec 3, 2019
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1068 Exploitation for Privilege Escalation6
  2. T1059 Command and Scripting Interpreter2
  3. T1078 Valid Accounts2
  4. T1203 Exploitation for Client Execution2
  5. T1222 File and Directory Permissions Modification1
  6. T1485 Data Destruction1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Dell