QID 375541
QID 375541: Dell Client Platform Security Update for Insufficient Access Control Vulnerability (DSA-2021-088)
Dell Client Platform is affected by an Insufficient Access Control Vulnerability in the Dell dbutil Driver. The vulnerability exists in the dbutil_2_3.sys driver which is installed on Dell Windows machines.
Affected Products
The vulnerable driver dbutil_2_3.sys was delivered to impacted systems in two ways: 1 via affected firmware update utility packages, and 2 via Dell Command Update, Dell Update, Alienware Update, Dell System Inventory Agent, or Dell Platform Tags
Successful exploitation of the vulnerability will allow escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.
Workaround:
Manually remove the dbutil_2_3.sys driver, following locations need to checks for the presence of the file
- C:\Users\username\AppData\Local\Temp
- C:\Windows\Temp
CVEs related to QID 375541
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| DSA-2021-088 |
|