CVE-2021-21551

HIGH8.8Pubblicata il 4 maggio 2021

Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.

Sfruttata attivamente

  • Nel catalogo CISA delle vulnerabilità sfruttate dal 31 mar 2022
  • Le agenzie federali statunitensi devono correggerla entro il 21 apr 2022 (direttiva BOD 22-01)
  • Primo attacco osservato 330 giorni dopo la divulgazione

Apply updates per vendor instructions.

Fonte: CISA KEV · 15 lug 2024 22 mag 2024 24 mar 2023 20 mar 2023 9 mar 2023 7 mar 2023

Punteggio CVSS8.8 / 10CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Tipo di debolezza (CWE)CWE-782
Vendordell

Prodotti coinvolti

VendorProdottoVersioni
delldbutil<= 2.3
dellalienware 14-
dellalienware 17 51m r2-
dellalienware area 51-
dellalienware asm100-
dellalienware asm100r2-
dellalienware m14xr2-
dellalienware m15 r4-
dellalienware m17xr4-
dellalienware m18xr2-
dellcanvas 27-
dellcheng ming 3967-
dellchengming 3967-
dellchengming 3977-
dellchengming 3980-
dellchengming 3988-
dellchengming 3990-
dellchengming 3991-
delldock wd15-
delldock wd19-
dellembedded box pc 5000-
dellg15 5510-
dellg3 3500-
dellg3 3579-
dellg3 3779-

Articoli correlati

This product uses the NVD API but is not endorsed or certified by the NVD.

Database CVE