HIGH
CVE-2021-21551
CVSS
7.8
KEV
Description
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.
Summary dbcve.org
The Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability allowing a local authenticated user to interact with the driver in ways that should be restricted. This can lead to privilege escalation to SYSTEM level, denial of service through driver manipulation, or information disclosure.
Mitigation
Apply the Dell security update that patches the dbutil_2_3.sys driver, or remove the driver if not required. Dell released updates addressing this vulnerability in April 2021.
Weakness (CWE)
CWE-782
EPSS Score
79.25%
Probability of exploitation in next 30 days
99.6th percentile
References
http://packetstormsecurity.com/files/162604/Dell-DBUtil_2_3.sys-IOCTL-Memory-Read-Write.html
Exploit, Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/162739/DELL-dbutil_2_3.sys-2.3-Arbitrary-Write-Privilege-Escalation.html
Exploit, Third Party Advisory, VDB Entry
https://www.dell.com/support/kbdoc/en-us/000186019/dsa-2021-088-dell-client-platform-security-update-for-dell-driver-insufficient-access-control-vulnerability
Mitigation, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-21551
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.