CVE-2026-61407: High severity Dell Watchdog Timer Driver vulnerability
Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell Watchdog Timer Driverto a version that resolves this vulnerability.Fixed in 2.0.0.1
Event History
Frequently Asked Questions
Which systems and attackers are in scope?
Systems running a Dell Watchdog Timer Driver version earlier than 2.0.0.1 are affected. Exploitation requires local access and a low-privileged account; it is not described as remotely exploitable.
What access is required for exploitation and what could it lead to?
An attacker needs local access and low privileges to interact with the exposed IOCTL. Successful exploitation could result in privilege escalation with high impact to confidentiality, integrity, and availability.
What is the available remediation?
Update the Dell Watchdog Timer Driver to version 2.0.0.1 or later. The provided information does not specify a workaround if updating cannot be performed immediately.