Ancient update driver endangers hundreds of millions of Dell computers

By
Follow google news

Allows kernel mode privilege escalation.

A vulnerable driver for firmware updates that has shipped with hundreds of millions of Dell desktops, laptops, notebooks and tablets could be abused by attackers to gain kernel-mode privileges for code and should be patched urgently.

Ancient update driver endangers hundreds of millions of Dell computers

SentinelOne researcher Kasif Dekel analysed the dbutil_2_3.sys driver for Windows which has shipped with Dell machines since 2009, and discovered five different flaws.

Four of them allow local privilege escalation through memory corruption and no input validation.

A fifth code logic problem in the driver could be used for denial of service attacks.

"The high severity flaws could allow any user on the computer, even without privileges, to escalate their privileges and run code in kernel mode," the researcher wrote.

"Among the obvious abuses of such vulnerabilities are that they could be used to bypass security products."

The bugs are tracked jointly with the Common Vulnerabilities and Exposures identifier CVE-2021-21551.

They are rated as an 8.8 out of 10 on the Common Vulnerabilities Scoring System version 3.

Dell has acknowledged the problem, which Dekel reported to the vendor on December 1 2020.

Working with Microsoft, Dell issued a new version in May this year that takes care of the vulnerability in the firmware updating package.

However, SentinelOne cautioned that the digital certificate for the older driver is yet to be revoked, which isn't best practice as the vulnerable version can be used in attacks.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

'Copy Fail' Linux privesc bug lay dormant in kernel since 2017

'Copy Fail' Linux privesc bug lay dormant in kernel since 2017

Medibank reveals attack vector and cost of 2022 security breach

Medibank reveals attack vector and cost of 2022 security breach

Incomplete fix for Fancy Bear exploit opens zero-click hole in Windows

Incomplete fix for Fancy Bear exploit opens zero-click hole in Windows

Log In

  |  Forgot your password?