Dell Watchdog Timer < 2.0.0.1 Privilege Escalation (DSA-2026-248)

high Nessus Plugin ID 339708

Synopsis

The Dell Watchdog Timer Driver installed on the remote Windows host is affected by a privilege escalation vulnerability.

Description

According to its self-reported version, the Dell Watchdog Timer kernel driver (WDTKernel.sys) on the remote Windows host is prior to 2.0.0.1. It is, therefore, affected by an exposed IOCTL with insufficient access control vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to privilege escalation.

Note that Nessus has not tested for this issue but has instead relied only on the driver's self-reported version number.

Solution

Update the Dell Watchdog Timer Driver to version 2.0.0.1 or later.

See Also

http://www.nessus.org/u?8becbc54

Plugin Details

Severity: High

ID: 339708

File Name: dell_watchdog_timer_dsa-2026-248.nasl

Version: 1.1

Type: Local

Agent: windows

Family: Windows

Published: 8/26/2026

Updated: 8/26/2026

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.76

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-61407

CVSS v3

Risk Factor: High

Base Score: 8.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Vulnerability Information

CPE: x-cpe:/a:dell:watchdog_timer_driver

Required KB Items: SMB/Registry/Enumerated, installed_sw/Dell Watchdog Timer Driver

Patch Publication Date: 8/17/2026

Vulnerability Publication Date: 8/18/2026

Reference Information

CVE: CVE-2026-61407

IAVA: 2026-A-0865