SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2021-21551

Dell dbutil Driver Insufficient Access Control Vulnerability

KEVHIGH 7.8EPSS 79.2%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 21 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
79.25% probability · 100th percentile
CISA KEV
Listed 31 March 2022 · due 21 April 2022
Weakness
CWE-782
Affected
dell/dbutil
Source
security_alert@emc.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2021-21551

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.