CVE-2025-22394

Dell Display Manager, versions prior to 2.3.2.18, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to code execution and possibly privilege escalation.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:display_manager:*:*:*:*:*:*:*:*

History

04 Feb 2025, 15:51

Type Values Removed Values Added
CPE cpe:2.3:a:dell:display_manager:*:*:*:*:*:*:*:*
Summary
  • (es) Dell Display Manager, versiones anteriores a la 2.3.2.18, contiene una vulnerabilidad de Time-of-check Time-of-use (TOCTOU). Un atacante con pocos privilegios y acceso local podría aprovechar esta vulnerabilidad, lo que provocaría la ejecución de código y posiblemente la escalada de privilegios.
References () https://www.dell.com/support/kbdoc/en-us/000267927/dsa-2025-033 - () https://www.dell.com/support/kbdoc/en-us/000267927/dsa-2025-033 - Vendor Advisory
First Time Dell
Dell display Manager

15 Jan 2025, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-15 05:15

Updated : 2025-02-04 15:51


NVD link : CVE-2025-22394

Mitre link : CVE-2025-22394

CVE.ORG link : CVE-2025-22394


JSON object : View

Products Affected

dell

  • display_manager
CWE
CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition