CVE-2021-21551
KEVHIGH 8.8EPSS 79.2%
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H - CVSS v2.0
- 4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 79.25% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-03-31
- Published
- 2021-05-04
- Updated
- 2025-10-21
Proof-of-concept exploits (17)
- http://packetstormsecurity.com/files/162604/Dell-DBUtil_2_3.sys-IOCTL-Memory-Read-Write.h…
- http://packetstormsecurity.com/files/162739/DELL-dbutil_2_3.sys-2.3-Arbitrary-Write-Privi…
- ColeHouston/Sunder225★ · 2025-01-18
- ColeHouston/theHandler-BOF47★ · 2025-08-05
- Eap2468/CVE-2021-215511★ · 2024-08-02
- IlanDudnik/CVE-2021-215510★ · 2025-01-12
- alfarom256/MCP-PoC79★ · 2022-10-31
- arnaudluti/PS-CVE-2021-215511★ · 2021-06-20
- ch3rn0byl/CVE-2021-2155124★ · 2021-05-21
- ihack4falafel/Dell-Driver-EoP-CVE-2021-2155132★ · 2022-02-24
- luke0x90/CVE-2021-215510★ · 2025-02-13
- mathisvickie/CVE-2021-2155159★ · 2021-11-16
- mzakocs/CVE-2021-21551-POC23★ · 2021-07-20
- nanabingies/CVE-2021-2155126★ · 2023-02-03
- tijme/kernel-mii85★ · 2023-05-07
- waldo-irc/CVE-2021-21551236★ · 2021-05-20
- bengabay1994/cve-2021-21551-PoC