| Thread Tools |
6th May 2021, 08:59 | #1 |
[M] Reviewer Join Date: May 2010 Location: Romania
Posts: 153,575
| Millions of Dells need an upgrade Michael finally fixed a 12-year-old vulnerability Hundreds of millions of Dell desktops, laptops, notebooks, and tablets will need to update their Dell DBUtil driver to fix a 12-year-old vulnerability that exposes systems to attacks. The bug, with the memorable name CVE-2021-21551, impacts version 2.3 of DBUtil, a Dell BIOS driver that allows the OS and system apps to interact with the computer’s BIOS and hardware. In a report published today and shared with The Record, security firm SentinelOne said it found a vulnerability that could allow threat actors to access driver functions and execute malicious code with SYSTEM and kernel-level privileges. Researchers said the DBUtil vulnerability could not be exploited over the internet to access unpatched systems remotely. Instead, threat actors who gained initial access to a computer, even to a low-level account, could abuse this bug to take complete control over the compromised PC — in what the security community typically describes as a privilege escalation vulnerability. This bug is nothing out of the ordinary. It is relatively typical for system drivers these days, many of which have been coded years ago and have not always followed secure coding practices. SentinelOne said it worked with Dell since December to make sure fixes are available. The company said it plans to release proof-of-concept code for CVE-2021-21551 on June 1. It recommended that system administrators and users apply the Dell DBUtil updates until then. CrowdStrike security expert Alex Ionescu said it was the third time that someone reported the same issue to the hardware vendor in two years. https://fudzilla.com/news/52815-mill...eed-an-upgrade |
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
SoundCloud will let DJs instantly mix millions of its tracks | Stefan Mileschin | WebNews | 0 | 19th October 2018 11:03 |
Dells adds 27-inch U2717D IPS InfinityEdge panel to lineup | Stefan Mileschin | WebNews | 0 | 31st January 2016 19:25 |
Dells says there will be no EMC sell-off | Stefan Mileschin | WebNews | 0 | 17th November 2015 17:37 |
The NSA has collected 'millions' of faces from the web | Stefan Mileschin | WebNews | 0 | 2nd June 2014 10:00 |
Microsoft losing millions on Surface | Stefan Mileschin | WebNews | 0 | 1st May 2014 16:23 |
Here's how the NSA can collect data from millions of PCs | Stefan Mileschin | WebNews | 0 | 13th March 2014 08:38 |
Millions Of People Don't Use The Internet | Stefan Mileschin | WebNews | 0 | 26th September 2013 10:23 |
Hyundai, Kia in $millions lawsuit over fuel fib | Stefan Mileschin | WebNews | 0 | 9th November 2012 07:35 |
AMD sold millions of G690 chipsets | jmke | WebNews | 0 | 2nd July 2007 15:20 |
To upgrade or not to upgrade that is the question | SuAside | General Madness - System Building Advice | 34 | 28th January 2007 21:15 |
Thread Tools | |
| |