Skip to main content

Dell Releases Security Updates

Vulnerability is being exploited in Dell products

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Vulnerability is being exploited in Dell products


Affected platforms

The following platforms are known to be affected:

All Dell systems running a Windows operating system and using the dbutil_2_3.sys driver


Threat details

Introduction

Dell has released a security advisory to address an insufficient access control vulnerability (CVE-2021-21551) that affects hundreds of products. Exploitation of this vulnerability may lead to a denial-of-service condition, escalation of privileges, or information disclosure if an attacker is able to gain local authenticated user access.

CVE-2021-21551 is the result of five flaws within the dbutil_2_3.sys driver, which is installed and loaded during the BIOS update process on affected systems.

Exploitation for CVE-2021-21551

Researchers from ESET have observed vulnerability CVE-2021-21551 being exploited by Advanced Persistent Threat (APT) groups to deploy a Windows rootkit. Affected organisations are encouraged to review Dell security advisory DSA-2021-088 and follow recommended remediation steps, applying the relevant updates.


Threat updates

Date Update
6 Oct 2022 Known exploitation

Cyber alert is being updated to reflect exploitation by known threat groups. 


Remediation advice

Affected organisations are encouraged to review Dell security advisory DSA-2021-088 and follow recommended remediation steps and apply the relevant updates. Dell has also released additional information about the advisory.


Last edited: 6 October 2022 5:17 pm