ZeroHour

CVE-2021-21551

KEV PoC ×2mass

Local Privilege Escalation in Dell dbutil_2_3.sys Driver

CISA: Dell dbutil Driver Insufficient Access Control Vulnerability

CVSS 3.1
7.8 high
EPSS
79%p100
Published
()
KEV added
AI analysis

CVE-2021-21551 is an insufficient access control flaw (CWE-782) in Dell's dbutil_2_3.sys driver, present on Dell systems for roughly 12 years before being patched. A local, authenticated user can trigger the flaw by sending crafted requests (IOCTLs) to the driver, gaining the ability to read and write arbitrary memory. An attacker who exploits it can escalate privileges (typically to kernel/SYSTEM level), cause a denial of service, or disclose information, making it a useful stepping stone for post-compromise attacks. Any Dell machine that shipped or ran the dbutil driver — used in Dell support and BIOS/BIOS-update tooling — is affected, and public reporting indicates hundreds of millions of Dell PCs are exposed. The flaw is actively exploited: it is listed in CISA's Known Exploited Vulnerabilities Catalog (added 2022-03-31), public PoCs exist, and the Lazarus APT reportedly used it in attacks to deploy a rootkit; EPSS puts the 30-day exploitation probability at 79.2%.

What to do: Apply Dell's updated driver/firmware per vendor instructions, as required by CISA's KEV catalog. Inventory your fleet for the dbutil_2_3.sys driver file (commonly found with Dell support tools and BIOS update utilities) and prioritize patching endpoints, since the bug requires only local user access. Hunt for signs of local privilege-escalation activity consistent with public PoCs, given documented Lazarus APT use to deploy a rootkit.

Affected
Dell dbutil driver (dbutil_2_3.sys)dbutil_2_3.sys as identified in the advisory; source data provides no detailed fixed-version range, so check for the presence of dbutil_2_3.sys on Dell systems
Estimated exposure
masshundreds of millions of Dell PCs (the driver was broadly distributed with Dell support/update tooling for over a decade) — Public reporting in the provided headlines states the vulnerable driver impacted 'hundreds of millions' of Dell PCs worldwide, reflecting the driver's wide bundling with Dell's support and BIOS-update utilities across many product…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.

CISA Known Exploited Vulnerability
Affected
Dell dbutil Driver
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
dell
Products
dbutil
Weakness
CWE-782
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news