Junglewise Threat Intelligence

CVE-2021-21551: Dell dbutil Driver Insufficient Access Control Vulnerability

CVE-2021-21551 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-03-31

Vendors: Dell.

Executive brief

The Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability (exposed IOCTL). A local authenticated attacker can exploit this to escalate privileges, cause a denial-of-service, or disclose sensitive information.

Affected products

  • Dell dbutil_2_3.sys driver up to (including) 2.3

Timeline

  • 2022-03-31: disclosed
  • 2022-03-31: kev added: Added to CISA Known Exploited Vulnerabilities Catalog