CVE-2021-21551

HIGH8.8Published on May 4, 2021

Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.

Actively exploited

  • In the CISA exploited-vulnerabilities catalogue since Mar 31, 2022
  • US federal agencies must remediate it by Apr 21, 2022 (BOD 22-01)
  • First attack observed 330 days after disclosure

Apply updates per vendor instructions.

Source: CISA KEV · Jul 15, 2024 May 22, 2024 Mar 24, 2023 Mar 20, 2023 Mar 9, 2023 Mar 7, 2023

CVSS score8.8 / 10CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weakness type (CWE)CWE-782
Vendorsdell

Affected products

VendorsProdottoVersioni
delldbutil<= 2.3
dellalienware 14-
dellalienware 17 51m r2-
dellalienware area 51-
dellalienware asm100-
dellalienware asm100r2-
dellalienware m14xr2-
dellalienware m15 r4-
dellalienware m17xr4-
dellalienware m18xr2-
dellcanvas 27-
dellcheng ming 3967-
dellchengming 3967-
dellchengming 3977-
dellchengming 3980-
dellchengming 3988-
dellchengming 3990-
dellchengming 3991-
delldock wd15-
delldock wd19-
dellembedded box pc 5000-
dellg15 5510-
dellg3 3500-
dellg3 3579-
dellg3 3779-

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database