← Vulnerability feed

Vulnerability record · CVE-2021-21551 · published 4 May 2021

CVE-2021-21551: Dell dbutil_2_3.sys driver insufficient access control privilege escalation

Dell · Dbutil

The Dell dbutil_2_3.sys driver contains insufficient access control that lets a local user reach privileged driver operations. It matters because the driver ships on many Dell client systems and the flaw enables elevation of privileges, denial of service, or information disclosure.

7.8 CVSS 3.1 High CISA KEV since 31 Mar 2022 EPSS 79% · top 0.4% CWE-782 · CWE-782
7.8CVSS 3.1 base score, v2 4.6
79%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityIt is in CISA KEV with public exploits and a very high EPSS score, though exploitation requires local authenticated access.

What it is

The Dell dbutil_2_3.sys driver contains insufficient access control that lets a local user reach privileged driver operations. It matters because the driver ships on many Dell client systems and the flaw enables elevation of privileges, denial of service, or information disclosure.

Impact

An attacker with local access gains the ability to escalate privileges, cause a denial of service, or read sensitive information on the affected host.

Attack surface

Reached locally through the driver's IOCTL interface; the CVSS vector (AV:L/PR:L/UI:N) indicates a local authenticated user is required and no user interaction is needed.

Exploitation

CISA added it to the KEV catalog on 2022-03-31 with a 2022-04-21 remediation due date, and public exploit references exist; EPSS 30-day probability is 0.79249 (99.58th percentile). No ransomware campaign use is documented.

What to do

  • Apply the Dell client platform security update per DSA-2021-088 (patch first).
  • Remove or replace the vulnerable dbutil_2_3.sys driver where it is not required.
  • Restrict local administrative and interactive access on affected endpoints.
  • Monitor for and block known exploit tooling targeting the driver's IOCTL interface.

Detection

  • Hunt for dbutil_2_3.sys present on endpoints and flag unpatched versions.
  • Monitor for unexpected loading of the dbutil driver or access to its device interface.
  • Alert on suspicious local privilege escalation behavior following driver IOCTL activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-21551 to the Known Exploited Vulnerabilities catalog on 31 March 2022 as "Dell dbutil Driver Insufficient Access Control Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 21 April 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-21551 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2021-21551), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.