Vulnerability record · CVE-2021-21551 · published 4 May 2021
CVE-2021-21551: Dell dbutil_2_3.sys driver insufficient access control privilege escalation
Dell · Dbutil
The Dell dbutil_2_3.sys driver contains insufficient access control that lets a local user reach privileged driver operations. It matters because the driver ships on many Dell client systems and the flaw enables elevation of privileges, denial of service, or information disclosure.
Description
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with public exploits and a very high EPSS score, though exploitation requires local authenticated access.
What it is
The Dell dbutil_2_3.sys driver contains insufficient access control that lets a local user reach privileged driver operations. It matters because the driver ships on many Dell client systems and the flaw enables elevation of privileges, denial of service, or information disclosure.
Impact
An attacker with local access gains the ability to escalate privileges, cause a denial of service, or read sensitive information on the affected host.
Attack surface
Reached locally through the driver's IOCTL interface; the CVSS vector (AV:L/PR:L/UI:N) indicates a local authenticated user is required and no user interaction is needed.
Exploitation
CISA added it to the KEV catalog on 2022-03-31 with a 2022-04-21 remediation due date, and public exploit references exist; EPSS 30-day probability is 0.79249 (99.58th percentile). No ransomware campaign use is documented.
What to do
- Apply the Dell client platform security update per DSA-2021-088 (patch first).
- Remove or replace the vulnerable dbutil_2_3.sys driver where it is not required.
- Restrict local administrative and interactive access on affected endpoints.
- Monitor for and block known exploit tooling targeting the driver's IOCTL interface.
Detection
- Hunt for dbutil_2_3.sys present on endpoints and flag unpatched versions.
- Monitor for unexpected loading of the dbutil driver or access to its device interface.
- Alert on suspicious local privilege escalation behavior following driver IOCTL activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-21551 to the Known Exploited Vulnerabilities catalog on 31 March 2022 as "Dell dbutil Driver Insufficient Access Control Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 21 April 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/162604/Dell-DBUtil_2_3.sys-IOCTL-Memory-Read-Write.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/162739/DELL-dbutil_2_3.sys-2.3-Arbitrary-Write-Privilege-Escalation.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.dell.com/support/kbdoc/en-us/000186019/dsa-2021-088-dell-client-platform-security-update-for-dell-driver-ins | MitigationVendor Advisory |
| http://packetstormsecurity.com/files/162604/Dell-DBUtil_2_3.sys-IOCTL-Memory-Read-Write.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/162739/DELL-dbutil_2_3.sys-2.3-Arbitrary-Write-Privilege-Escalation.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.dell.com/support/kbdoc/en-us/000186019/dsa-2021-088-dell-client-platform-security-update-for-dell-driver-ins | MitigationVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-21551 | US Government Resource |
Track CVE-2021-21551 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2021-21551), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.