CVE-2021-21551

Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:dbutil_2_3.sys:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:48

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/162604/Dell-DBUtil_2_3.sys-IOCTL-Memory-Read-Write.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/162604/Dell-DBUtil_2_3.sys-IOCTL-Memory-Read-Write.html - Exploit, Third Party Advisory, VDB Entry
References () http://packetstormsecurity.com/files/162739/DELL-dbutil_2_3.sys-2.3-Arbitrary-Write-Privilege-Escalation.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/162739/DELL-dbutil_2_3.sys-2.3-Arbitrary-Write-Privilege-Escalation.html - Exploit, Third Party Advisory, VDB Entry
References () https://www.dell.com/support/kbdoc/en-us/000186019/dsa-2021-088-dell-client-platform-security-update-for-dell-driver-insufficient-access-control-vulnerability - Mitigation, Vendor Advisory () https://www.dell.com/support/kbdoc/en-us/000186019/dsa-2021-088-dell-client-platform-security-update-for-dell-driver-insufficient-access-control-vulnerability - Mitigation, Vendor Advisory
CVSS v2 : 4.6
v3 : 7.8
v2 : 4.6
v3 : 8.8

17 Sep 2024, 19:47

Type Values Removed Values Added
CPE cpe:2.3:a:dell:dbutil_2_3.sys:-:*:*:*:*:*:*:* cpe:2.3:a:dell:dbutil_2_3.sys:*:*:*:*:*:*:*:*

16 Sep 2024, 23:15

Type Values Removed Values Added
Summary (en) Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required. (en) Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.

05 Oct 2023, 06:15

Type Values Removed Values Added
Summary Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required. Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.
CWE NVD-CWE-Other CWE-782

Information

Published : 2021-05-04 16:15

Updated : 2024-11-21 05:48


NVD link : CVE-2021-21551

Mitre link : CVE-2021-21551

CVE.ORG link : CVE-2021-21551


JSON object : View

Products Affected

dell

  • dbutil_2_3.sys
CWE
CWE-782

Exposed IOCTL with Insufficient Access Control

NVD-CWE-Other