CVE-2021-21551

Dell dbutil

Published 4 May 2021 · updated 17 Jun 2026 · Analyzed

7.8 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 31 Mar 2022, with a remediation deadline of 21 Apr 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.

References