It appears you have not yet registered with our community. To register please click here...

 
Go Back [M] > Madshrimps > WebNews
Millions of Dells need an upgrade Millions of Dells need an upgrade
FAQ Members List Calendar Search Today's Posts Mark Forums Read


Millions of Dells need an upgrade
Reply
 
Thread Tools
Old 6th May 2021, 08:59   #1
[M] Reviewer
 
Stefan Mileschin's Avatar
 
Join Date: May 2010
Location: Romania
Posts: 153,575
Stefan Mileschin Freshly Registered
Default Millions of Dells need an upgrade

Michael finally fixed a 12-year-old vulnerability

Hundreds of millions of Dell desktops, laptops, notebooks, and tablets will need to update their Dell DBUtil driver to fix a 12-year-old vulnerability that exposes systems to attacks.

The bug, with the memorable name CVE-2021-21551, impacts version 2.3 of DBUtil, a Dell BIOS driver that allows the OS and system apps to interact with the computer’s BIOS and hardware.

In a report published today and shared with The Record, security firm SentinelOne said it found a vulnerability that could allow threat actors to access driver functions and execute malicious code with SYSTEM and kernel-level privileges.

Researchers said the DBUtil vulnerability could not be exploited over the internet to access unpatched systems remotely. Instead, threat actors who gained initial access to a computer, even to a low-level account, could abuse this bug to take complete control over the compromised PC — in what the security community typically describes as a privilege escalation vulnerability.

This bug is nothing out of the ordinary. It is relatively typical for system drivers these days, many of which have been coded years ago and have not always followed secure coding practices.

SentinelOne said it worked with Dell since December to make sure fixes are available. The company said it plans to release proof-of-concept code for CVE-2021-21551 on June 1. It recommended that system administrators and users apply the Dell DBUtil updates until then.

CrowdStrike security expert Alex Ionescu said it was the third time that someone reported the same issue to the hardware vendor in two years.

https://fudzilla.com/news/52815-mill...eed-an-upgrade
Stefan Mileschin is offline   Reply With Quote
Reply


Similar Threads
Thread Thread Starter Forum Replies Last Post
SoundCloud will let DJs instantly mix millions of its tracks Stefan Mileschin WebNews 0 19th October 2018 11:03
Dells adds 27-inch U2717D IPS InfinityEdge panel to lineup Stefan Mileschin WebNews 0 31st January 2016 19:25
Dells says there will be no EMC sell-off Stefan Mileschin WebNews 0 17th November 2015 17:37
The NSA has collected 'millions' of faces from the web Stefan Mileschin WebNews 0 2nd June 2014 10:00
Microsoft losing millions on Surface Stefan Mileschin WebNews 0 1st May 2014 16:23
Here's how the NSA can collect data from millions of PCs Stefan Mileschin WebNews 0 13th March 2014 08:38
Millions Of People Don't Use The Internet Stefan Mileschin WebNews 0 26th September 2013 10:23
Hyundai, Kia in $millions lawsuit over fuel fib Stefan Mileschin WebNews 0 9th November 2012 07:35
AMD sold millions of G690 chipsets jmke WebNews 0 2nd July 2007 15:20
To upgrade or not to upgrade that is the question SuAside General Madness - System Building Advice 34 28th January 2007 21:15

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 14:59.


Powered by vBulletin® - Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
SEO by vBSEO