Improper access control in DBUtil - CVE-2021-21551
Published: May 5, 2021 / Updated: January 16, 2023
Vulnerability identifier: #VU52877
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-21551
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper access restrictions within the Dell dbutil driver dbutil_2_3.sys. A local user can run a specially crafted program to execute arbitrary code on the system with elevated privileges.
Affected software
DBUtil
How to mitigate CVE-2021-21551
Install updates from vendor's website.
Links to Public Exploits and PoC-codes
- Exploit #8741 - CVE-2021-21551 (Dell Driver EoP (CVE-2021-21551)) (January 16, 2023)
- Exploit #8077 - kernel-mii (Cobalt Strike (CS) Beacon Object File (BOF) foundation for kernel exploitation using CVE-2021-21551.) (June 26, 2022)
- Exploit #6703 - Dell-Driver-EoP-CVE-2021-21551 (Dell Driver EoP (CVE-2021-21551)) (September 5, 2021)
- Exploit #6541 - CVE-2021-21551-POC (An extended proof-of-concept for the CVE-2021-21551 Dell ‘dbutil_2_3.sys’ Kernel Exploit) (July 19, 2021)
- Exploit #5584 - DELL dbutil_2_3.sys 2.3 - Arbitrary Write to Local Privilege Escalation (LPE) (June 17, 2021)
- Exploit #5505 - PS-CVE-2021-21551 (Script to patch your domain computers about the CVE-2021-21551. Privesc on machines that have the driver dbutil_2_3.sys, installed by some DELL tools (BIOS updater, SupportAssist...)) (May 30, 2021)
- Exploit #5499 - CVE-2021-21551 (arbitrary kernel read/write in dbutil_2_3.sys, Proof of Concept Local Privilege Escalation to nt authority/system) (May 30, 2021)
- Exploit #5469 - CVE-2021-21551 () (May 24, 2021)
- Exploit #5409 - Dell DBUtil_2_3.sys IOCTL memmove (May 14, 2021)
- Exploit #5404 - CVE-2021-21551 (Exploit to SYSTEM for CVE-2021-21551) (May 13, 2021)