CVE-2021-21551 KEV EXPLOIT
8.8
HIGH · CVSS 3.1 · EPSS 79.2% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-04-21.
Description
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 79.25% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-782 |
| On CISA KEV | yes — remediate by 2022-04-21 |
| Public exploit | yes |
| Published | 2021-05-04 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Dell dbutil Driver Insufficient Access Control Vulnerability |
|---|---|
| Added | 2022-03-31 |
| Due | 2022-04-21 |
| Vendor / product | Dell / dbutil Driver |
| Ransomware use | none reported |
Affected (40)
| Vendor | Product |
|---|---|
| dell | alienware 14 |
| dell | alienware 17 51m r2 |
| dell | alienware area 51 |
| dell | alienware asm100 |
| dell | alienware asm100r2 |
| dell | alienware m14xr2 |
| dell | alienware m15 r4 |
| dell | alienware m17xr4 |
| dell | alienware m18xr2 |
| dell | canvas 27 |
| dell | cheng ming 3967 |
| dell | chengming 3967 |
| dell | chengming 3977 |
| dell | chengming 3980 |
| dell | chengming 3988 |
| dell | chengming 3990 |
| dell | chengming 3991 |
| dell | dbutil |
| dell | dock wd15 |
| dell | dock wd19 |
| dell | embedded box pc 5000 |
| dell | g15 5510 |
| dell | g3 3500 |
| dell | g3 3579 |
| dell | g3 3779 |
| dell | g5 5000 |
| dell | g5 5090 |
| dell | g5 5500 |
| dell | g5 5587 |
| dell | g5 5590 |
| dell | g7 7500 |
| dell | g7 7588 |
| dell | g7 7590 |
| dell | g7 7700 |
| dell | g7 7790 |
| dell | gaming g3 3590 |
| dell | inspiron 11-3162 |
| dell | inspiron 1122 |
| dell | inspiron 1210 |
| dell | inspiron 13 5370 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | DELL dbutil_2_3.sys 2.3 - Arbitrary Write to Local Privilege Escalation (LPE) | 2021-05-21 |
References
- http://packetstormsecurity.com/files/162604/Dell-DBUtil_2_3.sys-IOCTL-Memory-Read-Write.html
- http://packetstormsecurity.com/files/162739/DELL-dbutil_2_3.sys-2.3-Arbitrary-Write-Privilege-Escalation.html
- https://www.dell.com/support/kbdoc/en-us/000186019/dsa-2021-088-dell-client-platform-security-update-for-dell-driver-insufficient-access-control-vulnerability
- http://packetstormsecurity.com/files/162604/Dell-DBUtil_2_3.sys-IOCTL-Memory-Read-Write.html
- http://packetstormsecurity.com/files/162739/DELL-dbutil_2_3.sys-2.3-Arbitrary-Write-Privilege-Escalation.html
- https://www.dell.com/support/kbdoc/en-us/000186019/dsa-2021-088-dell-client-platform-security-update-for-dell-driver-insufficient-access-control-vulnerability
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-21551
→ the Explorer · watch your stack · NVD