Dell Releases Security Updates
Vulnerability is being exploited in Dell products
Summary
Vulnerability is being exploited in Dell products
Affected platforms
The following platforms are known to be affected:
All Dell systems running a Windows operating system and using the dbutil_2_3.sys driver
Threat details
Introduction
Dell has released a security advisory to address an insufficient access control vulnerability (CVE-2021-21551) that affects hundreds of products. Exploitation of this vulnerability may lead to a denial-of-service condition, escalation of privileges, or information disclosure if an attacker is able to gain local authenticated user access.
CVE-2021-21551 is the result of five flaws within the dbutil_2_3.sys driver, which is installed and loaded during the BIOS update process on affected systems.
Exploitation for CVE-2021-21551
Researchers from ESET have observed vulnerability CVE-2021-21551 being exploited by Advanced Persistent Threat (APT) groups to deploy a Windows rootkit. Affected organisations are encouraged to review Dell security advisory DSA-2021-088 and follow recommended remediation steps, applying the relevant updates.
Threat updates
| Date | Update |
|---|---|
| 6 Oct 2022 |
Known exploitation
Cyber alert is being updated to reflect exploitation by known threat groups. |
Remediation advice
Affected organisations are encouraged to review Dell security advisory DSA-2021-088 and follow recommended remediation steps and apply the relevant updates. Dell has also released additional information about the advisory.
Last edited: 6 October 2022 5:17 pm