CVE-2022-32498
Description
Dell EMC PowerStore, Versions prior to v3.0.0.0 contain a DLL Hijacking vulnerability in PSTCLI. A local attacker can potentially exploit this vulnerability to execute arbitrary code, escalate privileges, and bypass software allow list solutions, leading to system takeover or IP exposure.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
DLL hijacking in Dell PowerStore PSTCLI allows local attackers to execute arbitrary code and escalate privileges.
Vulnerability
Dell EMC PowerStore Command Line Interface (PSTCLI) for Windows and Linux (x64 and x86) versions prior to 3.0.0.0-1732745 contain a DLL hijacking vulnerability. The vulnerability exists in the PSTCLI tool, which is used to manage PowerStore systems. An attacker can place a malicious DLL in a directory that is searched before the legitimate DLL, causing the application to load the attacker's code. [1]
Exploitation
Exploitation requires local access to the system where PSTCLI is installed. The attacker must have the ability to write a malicious DLL to a location that is in the DLL search path of the PSTCLI executable. No user interaction beyond launching PSTCLI is needed; the attacker can trigger the vulnerability by having a user or automated process run the PSTCLI tool. [1]
Impact
Successful exploitation allows the attacker to execute arbitrary code in the context of the PSTCLI process. This can lead to privilege escalation, bypass of software allow list solutions, and potential system takeover or exposure of sensitive IP. The attacker gains the privileges of the user running PSTCLI, which may be elevated if run as administrator. [1]
Mitigation
Dell has released updated versions of the PSTCLI tool: 3.0.0.0-1732745 for Windows and Linux (x64 and x86). Users should upgrade to these versions. The update is available from Dell's support site. No workaround is mentioned; upgrading is the recommended mitigation. [1]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <3.0.0.0
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.dell.com/support/kbdoc/000201283mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.