CVE-2021-21551
Dell dbutil Driver Insufficient Access Control Vulnerability
- Published
- May 4, 2021
- Updated
- Oct 21, 2025
- Assigning CNA
- dell
- Evidence observed
- May 21, 2021
Dell dbutil Driver Insufficient Access Control Vulnerability
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HHigh · next 30 days
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.
Proof-of-concept exploit for CVE-2021-21551 targeting Dell's dbutil_2_3 driver to achieve code execution on systems with HVCI disabled.
Dell Driver EoP (CVE-2021-21551)
Proof-of-concept exploit for CVE-2021-21551: Windows local privilege escalation via Dell dbutil_2_3.sys driver. Implements read/write primitives, shellcode allocation, SMEP bypass, and HAL dispatch pointer overwrite.
An extended proof-of-concept for the CVE-2021-21551 Dell ‘dbutil_2_3.sys’ Kernel Exploit
Exploit to SYSTEM for CVE-2021-21551
This repo contain a PoC I have done when blind analysis the dbutil_2_3.sys driver for vulnerability. This was created by personal analysis without looking at writeups or even know which CVE exist in this driver. All the knowledge I have is that this driver is vulnerable in some way.
Proof of concept exploit for CVE-2021-21551
Exploit implementation for CVE-2021-21551
Dell Driver EoP (CVE-2021-21551)
Cobalt Strike (CS) Beacon Object File (BOF) foundation for kernel exploitation using CVE-2021-21551.
Paolo Stagno · windows · May 21, 2021
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.