CVE-2026-59914 in Dell Display and Peripheral Manager (DDPM) carries a 7.8 CVSS but an EPSS score of only 0.00129. The divergence is not a reason to deprioritize — it reflects a systematic blind spot in exploitation prediction models, not the absence of real risk. DDPM runs as a Windows service with elevated privileges to calibrate displays and communicate with monitors over USB-C and DisplayPort channels. The 'Authentication Bypass by Spoofing' classification indicates the software trusts hardware identity signals — likely Dell monitor firmware signatures or peripheral handshake protocols — that a low-privilege user can manipulate to impersonate legitimate hardware and inject code into the privileged service context.
This is a known vulnerability class: HP Support Assistant, Lenovo System Update, and Realtek audio drivers have all exhibited the same pattern of privileged OEM software implementing fragile hardware trust assumptions. The EPSS model weights remote and internet-facing vectors heavily because those surfaces generate the sensor data that feeds its training set. Local privilege escalation in pre-installed vendor bloatware operates below that radar.
Treat this as a SYSTEM-privileged local EoP vector regardless of the low EPSS. Verify whether DDPM runs as a service on your Dell endpoints and confirm the version is 2.3.0.17 or later — Dell's advisory references this as the fixed release, but no CVE publication date or advisory ID was provided, which itself signals limited vendor transparency. If you cannot confirm patching, treat DDPM as an active risk: a low-privilege user who gains code execution (through any other flaw or even malicious insider) can use this to escalate to SYSTEM and persist across reboots. The blast radius extends beyond the OS — firmware-level components that negotiate with DDPM inherit the trust compromise. Prioritize inventorying DDPM across your fleet, validate the patch status, and consider disabling the service if display calibration is not required in your environment.