CVE-2021-21551
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Dell dbutil Driver Insufficient Access Control Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 53% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-782
מוצרים מושפעים
dell: dbutil; dell: alienware 14; dell: alienware 17 51m r2; dell: alienware area 51; dell: alienware asm100; dell: alienware asm100r2; dell: alienware m14xr2; dell: alienware m15 r4; dell: alienware m17xr4; dell: alienware m18xr2; dell: canvas 27; dell: cheng ming 3967; dell: chengming 3967; dell: chengming 3977; dell: chengming 3980
קישורים
- https://www.dell.com/support/kbdoc/en-us/000186019/dsa-2021-088-dell-client-pl… MitigationVendor Advisory
- https://www.dell.com/support/kbdoc/en-us/000186019/dsa-2021-088-dell-client-pl… MitigationVendor Advisory
- http://packetstormsecurity.com/files/162604/Dell-DBUtil_2_3.sys-IOCTL-Memory-R… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/162739/DELL-dbutil_2_3.sys-2.3-Arbitrary-… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/162604/Dell-DBUtil_2_3.sys-IOCTL-Memory-R… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/162739/DELL-dbutil_2_3.sys-2.3-Arbitrary-… ExploitThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource