On May 4th, researchers as SentinelOne disclosed four vulnerabilities under one CVE number for Dell’s firmware update driver dbutil_2_3.sys. Four out of the five vulnerabilities allow an attacker to elevate from no privileges to kernel-level privileges by exploiting the vulnerable driver. This driver came preinstalled to every new Windows device produced by Dell and has been in use since 2009. While there have been varying versions of the driver, the estimate for affected devices is hundreds of millions as OEM updates like bios and firmware updates are often considered out of band by individual consumers and organizations alike. However, despite the updater’s end-of-life date being many years past, Dell has already begun to push the update and it is available to devices now.
12 Essentials for a Successful SOC Partnership
As cyber threats continue to impact businesses of all sizes, the need for round-the-clock security