SentinelLabs reported that CVE-2021-21551 affected a Dell BIOS update driver preinstalled on a vast number of consumer and enterprise systems, exposing potentially hundreds of millions of computers to local privilege escalation. The issue involved multiple flaws in the dbutil driver, which could allow an attacker with local access to escalate privileges to kernel mode, bypass security controls, and execute arbitrary code at the highest level of the operating system.
Because the vulnerable driver was broadly distributed through Dell firmware update utilities and support tools, the exposure spanned many device models and persisted even after software updates in some environments. The report warned that successful exploitation could enable attackers to disable security products, maintain persistence, and gain deep control over affected endpoints, prompting the need for driver removal, vendor patches, and verification that vulnerable components were fully remediated across fleets.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Dell issued a security advisory and remediation steps for CVE-2021-21551, including an updated driver and instructions for removing the vulnerable dbutil component from affected systems. The response addressed the risk of abuse by local attackers leveraging the flawed driver.
Multiple privilege-escalation vulnerabilities in Dell's dbutil BIOS update driver were publicly disclosed under CVE-2021-21551, exposing hundreds of millions of Dell systems to local escalation and related attacks. The disclosure identified the driver as broadly present across consumer and enterprise devices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
sentinelone.com
Open sourcedocs.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.