/?pid=22563

Updated:12:37 PM EST Mar 01


this is ggmania.com subsite Hundreds of Millions of Dell Laptops and Desktops Vulnerable - TechAmok

Hundreds of Millions of Dell Laptops and Desktops Vulnerable - [security]
05:50 PM EDT - May,05 2021 - post a comment

Dell notebooks and desktops dating all the way back since 2009 - hundreds of millions of them the PC giant has shipped since - are vulnerable to unauthorized privilege escalation attacks, due to a faulty OEM driver the company uses to update the computer's BIOS or UEFI firmware, according to findings by cybersecurity researchers at SentinelLabs. "DBUtil," a driver that Dell machines load during automated or unattended BIOS/UEFI update processes initiated by the user from within the OS, is found to have vulnerabilities that malware can exploit to "escalate privileges from a non-administrator user to kernel mode privileges." SentinelLabs chronicled its findings in CVE-2021-21551, which details five individual flaws. Two of these point out flaws that can escalate user privileges through controlled memory corruption, two with lack of input validation; and one with denial of service. Organizations that have remote updates enabled for their client machines are at risk, since the flaw can be exploited over network. "An attacker with access to an organization's network may also gain access to execute code on unpatched Dell systems and use this vulnerability to gain local elevation of privilege. Attackers can then leverage other techniques to pivot to the broader network, like lateral movement," writes SentielLabs in its paper. The good news here, is that SentinelLabs has been working with Dell before going public, and a patched DBUtil driver is ready. The company now stares at the daunting task of pushing patched drivers to potentially hundreds of millions of client PCs it shipped since 2009. The company put out a security advisory that describes CVE-2021-21551 to its end-users, and recommends the next course of action.


Add your comment (free registrationrequired)

Short overview of recent news articles

Mar,01 2026 Anghami CEO Open-Sources Powerful Real-Time Global War Monitor
Mar,01 2026 Chinese Developers Unleash Blazing-Fast Android AI Agent with
Mar,01 2026 Claude Surges to #1 on App Store as ChatGPT Faces Boycott Backlash
Feb,28 2026 Google Reveals Key New Features of Android 17
Feb,28 2026 OLED Gaming Monitors Are Finally Affordable
Feb,28 2026 OpenAI's KYC Partner Exposed in Surveillance Scandal as ChatGPT
Feb,28 2026 Pentagon Blacklists Anthropic Over AI Safeguards; OpenAI Secures
Feb,27 2026 Have RAM and GPU Prices Peaked?
Feb,27 2026 Zoom 'Update' Trap: Fake Site Infects 1,437 Users with Spyware in
Feb,27 2026 Stop WASTING Money on Fancy RAM
Feb,27 2026 Drunk AI robot
Feb,26 2026 AirSnitch Exposes Critical Flaw: Wi-Fi Client Isolation Broken in
Feb,26 2026 Revolutionary Ultrasonic Knife Hits Kitchens: C-200 Vibrates for
Feb,26 2026 Apple Scores Historic NATO Security Clearance: iPhone and iPad First
Feb,26 2026 Kali Linux Goes AI-Powered: Claude Now Runs Your Pen Tests in Plain
Feb,26 2026 Resident Evil Requiem - Stunning on PS5 Pro + PS5/Xbox Series X|S
Feb,26 2026 Samsung Galaxy S26 Ultra Flexes Hardware Muscle Over iPhone 17 Pro
Feb,26 2026 The Galaxy S26 Ultra has a 'wow' feature with video Lock
Feb,26 2026 I built the most BORING PC possible... and here is why it's
Feb,26 2026 Micron Blasts GDDR7 as Gaming Bottleneck While Nvidia's RTX 50
Feb,26 2026 UK Tightens Grip on Streaming Giants: Age Verification Now Mandatory
Feb,25 2026 Samsung Previews New AI Features Ahead of Flagship Phone Launch
Feb,25 2026 China's DeepSeek Bars Nvidia and AMD from New AI Model, Boosts
Feb,25 2026 Avast Impersonation Scam: Fake Site Tricks Users into Handing Over
Feb,25 2026 Microsoft Pulls the Plug: Windows Server 2016 and 2016-Era Windows
Feb,25 2026 I Scrapped 13 MACHINES to Prove a Point: STOP BUYING These Brands!
Feb,25 2026 How Stealthy was the 7zip Malware and how to spot it?
Feb,25 2026 Microsoft Drops Fresh Non-Security Boost for Windows 11 24H2 and
Feb,24 2026 Game-Changer: ASML's 1kW EUV Upgrade Promises 50% Chip Production
Feb,24 2026 This Outstanding Cooling Technology Might Have No Future
Feb,24 2026 AMD Strix Halo 395 vs Intel Panther Lake - Real Benchmarks
Feb,24 2026 Anthropic published a blog post saying Claude can modernize COBOL
Feb,24 2026 WhatsApp Goes Beyond 2FA: Extra Password Layer Makes Accounts Nearly
Feb,24 2026 Google Chrome Gets February 23 Security Boost with 3 High Fixes
Feb,23 2026 Stargate Stalls: OpenAI's $500B Dream Hits Roadblocks as $14B 2026
Feb,23 2026 Google Crushes Cyber Threats: Blocks 1.75 Million Bad Apps and Bans
Feb,22 2026 Bitcoin Miner Bitdeer Sells Everything: Treasury Hits Zero in AI
Feb,22 2026 HW News - More Valve RAM Shortages, Tariffs Ruling, AI Causes PS6
Feb,22 2026 Microsoft's Deep Integration of Copilot in Windows 11 Raises
Feb,22 2026 Elon Musk Confirms X Money Now Live in Internal Beta for Employees,
>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs