Vulnerability Description
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Dbutil | <= 2.3 |
| Dell | Alienware 14 | - |
| Dell | Alienware 17 51M R2 | - |
| Dell | Alienware Area 51 | - |
| Dell | Alienware Asm100 | - |
| Dell | Alienware Asm100R2 | - |
| Dell | Alienware M14Xr2 | - |
| Dell | Alienware M15 R4 | - |
| Dell | Alienware M17Xr4 | - |
| Dell | Alienware M18Xr2 | - |
| Dell | Canvas 27 | - |
| Dell | Cheng Ming 3967 | - |
| Dell | Chengming 3967 | - |
| Dell | Chengming 3977 | - |
| Dell | Chengming 3980 | - |
| Dell | Chengming 3988 | - |
| Dell | Chengming 3990 | - |
| Dell | Chengming 3991 | - |
| Dell | Dock Wd15 | - |
| Dell | Dock Wd19 | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/162604/Dell-DBUtil_2_3.sys-IOCTL-Memory-ReaExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/162739/DELL-dbutil_2_3.sys-2.3-Arbitrary-WrExploitThird Party AdvisoryVDB Entry
- https://www.dell.com/support/kbdoc/en-us/000186019/dsa-2021-088-dell-client-platMitigationVendor Advisory
- http://packetstormsecurity.com/files/162604/Dell-DBUtil_2_3.sys-IOCTL-Memory-ReaExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/162739/DELL-dbutil_2_3.sys-2.3-Arbitrary-WrExploitThird Party AdvisoryVDB Entry
- https://www.dell.com/support/kbdoc/en-us/000186019/dsa-2021-088-dell-client-platMitigationVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-US Government Resource
FAQ
What is CVE-2021-21551?
CVE-2021-21551 is a vulnerability with a CVSS score of 8.8 (HIGH). Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user acce...
How severe is CVE-2021-21551?
CVE-2021-21551 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-21551?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Dbutil, Dell Alienware 14, Dell Alienware 17 51M R2, Dell Alienware Area 51, Dell Alienware Asm100.