Skip to content
COOEY

EXPOSURES › CVE-2021-21551

CVE-2021-21551

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-31 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-21551 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatchedprivilege-escalation

Dell's dbutil driver had an insufficient access control flaw allowing privilege escalation, DoS, or data leaks.

The Dell dbutil driver suffered from insufficient access controls, enabling attackers to escalate privileges, cause denial-of-service, or leak information. For DIB organizations, this highlights the risk of unpatched vendor components and the need to rigorously validate third-party driver integrity. Organizations should ensure all vendor-supplied drivers are patched and monitored for known vulnerabilities.

Shame score — A known access control flaw in a vendor driver that could lead to privilege escalation and data exposure, indicating a lack of robust security design and patching discipline.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.