Skip to main content

CVE-2021-21551

8.8
HIGHCVSS v3.1 Base Score
71.41%
HIGH RiskEPSS (99th percentile)
KEV

Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.

Published: 5/4/2021
Modified: 10/28/2025
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

Dell dbutil Driver Insufficient Access Control Vulnerability

Vendor / Product:

Dell dbutil Driver

Required Action:

Apply updates per vendor instructions.

Due Date: 4/21/2022(OVERDUE)
Added to KEV:

3/31/2022

Notes:

https://nvd.nist.gov/vuln/detail/CVE-2021-21551

Vulnerability Summary

CVSS v3 Score

8.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVSS v2 Score

4.6

AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS Score (Exploitation Probability)

71.41%HIGH Exploitation Risk
99th percentile

This vulnerability has a 71.41% probability of being exploited in the next 30 days, ranking higher than 99% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-782)

Similar SeverityHIGH