Category: IT|May 8, 2021 | Author: Admin

Firmware vulnerability affects "millions" of PCs

Share on

Major vulnerabilities have been identified in Dell's firmware update driver that could allow attackers to access core-level code in millions of Dell PCs delivered for more than ten years.

Two years to reach a solution
SentinelLabs reported the vulnerability to Dell in December last year and has posted a detailed blog with all the information. Alex Ionescu from Crowdstike says that it took "three separate companies two years" to get a solution.

SentinelLabs notes that there are five errors in a single CVE (Common Vulnerabilities and Exposures is a reference for publicly known vulnerabilities and exposures) assigned by Dell: Two memory corruption issues, two input validation issues, and one code logic issue that could lead to a DDoS (Denial of Service) attack. The problem lies in the driver ‘dbutil_2_3.sys’ which is used in several firmware update tools for Dell and Alienware systems, including BIOS updates.

Dell has released a security advisory (DSA-2021-088) and made available updated packages for Windows that can be downloaded manually.

Risk minimization is recommended
The company recommends reducing the risk. This includes removing the driver ‘dbutil_2_3.sys’ from the PC and updating the driver manually, or waiting for the updated driver to download automatically. To remove the driver, the company recommends one of two:

  • Option 1 (Recommended): Download and run the Dell Security Advisory Update - DSA-2021-088 Utility.

  • Option 2: Manually remove the vulnerable dbutil_2_3.sys driver:

 

Step A:
Find dbutil_2_3.sys i
C: \ Users \\ AppData \ Local \ Temp
or
C: \ Windows \ Temp

Step B:
Select the file dbutil_2_3.sys, hold down shift and press Del to permanently delete it.

 

No indications of exploitation of the vulnerability
SentinelLabs says that there are no indications that the vulnerabilities have been exploited. Still, they recommend both businesses and consumers to update as it affects "hundreds of millions" of PCs.

Sources: SentinelLabs

Sponsored Ads:

Comments:


Now Tesla can do something completely new

Category: General|Jul 4, 2022 | Author: Admin

"Google pushes users into comprehensive monitoring"

Category: Google|Jul 3, 2022 | Author: Admin

In this country, Apple must comply with the new iPhone law

Category: Apple|Jul 2, 2022 | Author: Admin

Are you tired of iPhone? Now Google makes it easy

Category: Google|Jul 1, 2022 | Author: Admin

The EU extends its 'Roam-like-at-home' mobile service rule through 2032

Category: IT|Jun 30, 2022 | Author: Admin

Apple's important iPhone project may have failed

Category: Apple|Jun 29, 2022 | Author: Admin

Dramatic Netflix message: announces they are losing two million customers

Category: General|Jun 28, 2022 | Author: Admin

This is how mobile cameras get better with a shrunken Samsung sensor

Category: IT|Jun 27, 2022 | Author: Admin

Now the PlayStation 5 screens come with 4K and 144Hz

Category: General|Jun 26, 2022 | Author: Admin

AirPods get better sound quality - much about AirPods Pro 2 revealed

Category: Apple|Jun 25, 2022 | Author: Admin

The day is here: all you have to do is launch your Playstation

Category: General|Jun 24, 2022 | Author: Admin

This card holds the record

Category: IT|Jun 23, 2022 | Author: Admin

Russians refuse to download Windows 11 and 10

Category: Microsoft|Jun 22, 2022 | Author: Admin

Tesla is banned in this city

Category: General|Jun 21, 2022 | Author: Admin

Everyone with Sonos must know the super-tricks this button can

Category: IT|Jun 20, 2022 | Author: Admin
more