{"id":777,"date":"2021-05-06T08:48:55","date_gmt":"2021-05-06T13:48:55","guid":{"rendered":"https:\/\/www.echorequest.com\/?p=777"},"modified":"2021-05-06T08:48:55","modified_gmt":"2021-05-06T13:48:55","slug":"dell-hit-hard-urgent-security-risks-hundreds-of-millions-systems-affected","status":"publish","type":"post","link":"https:\/\/www.echorequest.com\/?p=777","title":{"rendered":"Dell hit hard..Urgent Security risks&#8230;HUNDREDS OF MILLIONS systems affected"},"content":{"rendered":"\n<p>It&#8217;s been awhile since I&#8217;ve posted anything from my line of work &#8211; but this one is pretty large and I just wanted to give my friends a heads up.  Dell has a driver that can be used by anyone that has access to your laptop, workstation, server etc&#8230;to gain admin rights to your system from a simple standard user account.  They are working on and just released a new firmware update utility to mitigate this risk.<\/p>\n\n\n\n<p>I urge anyone to make sure you apply updates &#8211; I would start by reading and following the Dell announcment: <\/p>\n\n\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-in\/000186019\/dsa-2021-088-dell-client-platform-security-update-for-dell-driver-insufficient-access-control-vulnerability\" data-type=\"URL\" data-id=\"https:\/\/www.dell.com\/support\/kbdoc\/en-in\/000186019\/dsa-2021-088-dell-client-platform-security-update-for-dell-driver-insufficient-access-control-vulnerability\">https:\/\/www.dell.com\/support\/kbdoc\/en-in\/000186019\/dsa-2021-088-dell-client-platform-security-update-for-dell-driver-insufficient-access-control-vulnerability <\/a><\/p>\n\n\n\n<p>Want to geek out and see who found it and more &#8211; follow:<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-wp-embed is-provider-sentinellabs wp-block-embed-sentinellabs\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"wp-embedded-content\" data-secret=\"wX3nOatUHv\"><a href=\"https:\/\/labs.sentinelone.com\/cve-2021-21551-hundreds-of-millions-of-dell-computers-at-risk-due-to-multiple-bios-driver-privilege-escalation-flaws\/\">CVE-2021-21551- Hundreds Of Millions Of Dell Computers At Risk Due to Multiple BIOS Driver Privilege Escalation Flaws<\/a><\/blockquote><iframe loading=\"lazy\" class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; clip: rect(1px, 1px, 1px, 1px);\" title=\"&#8220;CVE-2021-21551- Hundreds Of Millions Of Dell Computers At Risk Due to Multiple BIOS Driver Privilege Escalation Flaws&#8221; &#8212; SentinelLabs\" src=\"https:\/\/labs.sentinelone.com\/cve-2021-21551-hundreds-of-millions-of-dell-computers-at-risk-due-to-multiple-bios-driver-privilege-escalation-flaws\/embed\/#?secret=wX3nOatUHv\" data-secret=\"wX3nOatUHv\" width=\"600\" height=\"338\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe>\n<\/div><\/figure>\n\n\n\n<p>and: <\/p>\n\n\n\n<p><a href=\"https:\/\/thehackernews.com\/2021\/05\/bios-privesc-bug-affects-hundreds-of.html\">https:\/\/thehackernews.com\/2021\/05\/bios-privesc-bug-affects-hundreds-of.html<\/a><\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>It&#8217;s been awhile since I&#8217;ve posted anything from my line of work &#8211; but this one is pretty large and I just wanted to give my friends a heads up. Dell has a driver that can be used by anyone that has access to your laptop, workstation, server etc&#8230;to gain admin rights to your system [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[],"class_list":["post-777","post","type-post","status-publish","format-standard","hentry","category-geek","post-preview"],"_links":{"self":[{"href":"https:\/\/www.echorequest.com\/index.php?rest_route=\/wp\/v2\/posts\/777","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.echorequest.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.echorequest.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.echorequest.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.echorequest.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=777"}],"version-history":[{"count":1,"href":"https:\/\/www.echorequest.com\/index.php?rest_route=\/wp\/v2\/posts\/777\/revisions"}],"predecessor-version":[{"id":778,"href":"https:\/\/www.echorequest.com\/index.php?rest_route=\/wp\/v2\/posts\/777\/revisions\/778"}],"wp:attachment":[{"href":"https:\/\/www.echorequest.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=777"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.echorequest.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=777"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.echorequest.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=777"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}