HIGH🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2021-21551

CVSS 8.8v3.1pub. 2021-05-04upd. 2025-10-28

Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Dell Alienware 14

    HW
    Dell
    all versions
  • Dell Alienware 17 51m R2

    HW
    Dell
    all versions
  • Dell Alienware Area 51

    HW
    Dell
    all versions
  • Dell Alienware Asm100

    HW
    Dell
    all versions
  • Dell Alienware Asm100r2

    HW
    Dell
    all versions
  • Dell Alienware M14xr2

    HW
    Dell
    all versions
  • Dell Alienware M15 R4

    HW
    Dell
    all versions
  • Dell Alienware M17xr4

    HW
    Dell
    all versions
  • Dell Alienware M18xr2

    HW
    Dell
    all versions
  • Dell Canvas 27

    HW
    Dell
    all versions
  • Dell Chengming 3967

    HW
    Dell
    all versions
  • Dell Cheng Ming 3967

    HW
    Dell
    all versions
  • Dell Chengming 3977

    HW
    Dell
    all versions
  • Dell Chengming 3980

    HW
    Dell
    all versions
  • Dell Chengming 3988

    HW
    Dell
    all versions
  • Dell Chengming 3990

    HW
    Dell
    all versions
  • Dell Chengming 3991

    HW
    Dell
    all versions
  • Dell Dbutil

    APP
    Dell
    ≤ 2.3
  • Dell Dock Wd15

    HW
    Dell
    all versions
  • Dell Dock Wd19

    HW
    Dell
    all versions
  • Dell Embedded Box Pc 5000

    HW
    Dell
    all versions
  • Dell G15 5510

    HW
    Dell
    all versions
  • Dell G3 3500

    HW
    Dell
    all versions
  • Dell G3 3579

    HW
    Dell
    all versions
  • Dell G3 3779

    HW
    Dell
    all versions
  • Dell G5 5000

    HW
    Dell
    all versions
  • Dell G5 5090

    HW
    Dell
    all versions
  • Dell G5 5500

    HW
    Dell
    all versions
  • Dell G5 5587

    HW
    Dell
    all versions
  • Dell G5 5590

    HW
    Dell
    all versions

CISA KEV — detailsi

Vendori
Dell
Producti
dbutil Driver
Added to KEVi
March 31, 2022
Remediation deadline (US Federal)i
April 21, 2022(overdue)
Required action (CISA)i

Apply updates per vendor instructions.

CISA descriptioni

Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 21 kwietnia 2022
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2024-39584HIGH8.2same product

Dell Client Platform BIOS contains a Use of Default Cryptographic Key Vulnerability. A high privileged attack...

CVE-2024-32860HIGH7.5same product

Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed compo...

CVE-2024-32858HIGH7.5same product

Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed compo...

CVE-2024-32859HIGH7.5same product

Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed compo...

CVE-2024-22429HIGH7.5same product

Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with admin...