peter bassill · operator
$ cve CVE-2021-21551 JSON

CVE-2021-21551 KEV EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 79.2% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-04-21.

Description

Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS79.25% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-782
On CISA KEVyes — remediate by 2022-04-21
Public exploityes
Published2021-05-04
Last modified2026-06-17

CISA KEV

NameDell dbutil Driver Insufficient Access Control Vulnerability
Added2022-03-31
Due2022-04-21
Vendor / productDell / dbutil Driver
Ransomware usenone reported

Affected (40)

VendorProduct
dellalienware 14
dellalienware 17 51m r2
dellalienware area 51
dellalienware asm100
dellalienware asm100r2
dellalienware m14xr2
dellalienware m15 r4
dellalienware m17xr4
dellalienware m18xr2
dellcanvas 27
dellcheng ming 3967
dellchengming 3967
dellchengming 3977
dellchengming 3980
dellchengming 3988
dellchengming 3990
dellchengming 3991
delldbutil
delldock wd15
delldock wd19
dellembedded box pc 5000
dellg15 5510
dellg3 3500
dellg3 3579
dellg3 3779
dellg5 5000
dellg5 5090
dellg5 5500
dellg5 5587
dellg5 5590
dellg7 7500
dellg7 7588
dellg7 7590
dellg7 7700
dellg7 7790
dellgaming g3 3590
dellinspiron 11-3162
dellinspiron 1122
dellinspiron 1210
dellinspiron 13 5370

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD