Dell DBUtil_2_3.sys driver flaw, long patched, recorded only as the second vulnerable driver Cisco Talos observed the SPECTRE implant loading as its kernel read/write primitive. Not a new or in-window disclosure.
cve · CVE-2021-21551 single-source
Coverage
1
first 2026-08-23 → last 2026-09-29
Latest activity
2026-08-23
A cross-platform implant that blinds callback-dependent endpoint security products to process, thread and…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, telco, technology · regions: europe
Sources cited
1
1 hosts
Action items (1)
Do-now tasks recorded on the entries about CVE-2021-21551, newest first. Check the date before acting on an older one.
- Check whether RTCore64.sys and DBUtil_2_3.sys can load in your estate; Microsoft's vulnerable-driver blocklist covers both, and confirming it is enforced (rather than merely available) removes this implant's entire kernel-write path.2026-08-23CVE-2019-16098 +1
Defender insights
What each entry about CVE-2021-21551 tells a defender to do, newest first.
Triage
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (11 across 6 tactics)
11 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- Privilege EscalationProcess Injection: Asynchronous Procedure Call · Process Injection: Process Hollowing · Exploitation for Privilege Escalation · Access Token Manipulation: Token Impersonation/Theft
- StealthRootkit · Obfuscated Files or Information · Process Injection: Asynchronous Procedure Call · Process Injection: Process Hollowing · Access Token Manipulation: Token Impersonation/Theft
- Defense ImpairmentDisable or Modify Tools
- Credential AccessOS Credential Dumping: Security Account Manager · Credentials from Password Stores: Credentials from Web Browsers
- Command and ControlApplication Layer Protocol: Web Protocols
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · ATT&CK page ↗
Privilege Escalation TA0004
T1055.004Process Injection: Asynchronous Procedure Call×1
Adversaries may inject malicious code into processes via the asynchronous procedure call (APC) queue in order to evade process-based defenses as well as possibly elevate privileges. APC injection is a method of executing arbitrary code in the address space of a separate live process.
Evidence: 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · ATT&CK page ↗
T1055.012Process Injection: Process Hollowing×1
Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses. Process hollowing is a method of executing arbitrary code in the address space of a separate live process.
Evidence: 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · ATT&CK page ↗
T1068Exploitation for Privilege Escalation×1
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
Evidence: 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · ATT&CK page ↗
T1134.001Access Token Manipulation: Token Impersonation/Theft×1
Adversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access controls. For example, an adversary can duplicate an existing token using `DuplicateToken` or `DuplicateTokenEx`. The token can then be used with `ImpersonateLoggedOnUser` to allow the calling thread to impersonate a logged on user's security context, or with `SetThreadToken` to assign the impersonated token to a thread.
Evidence: 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · ATT&CK page ↗
Stealth TA0005
T1014Rootkit×1
Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are programs that hide the existence of malware by intercepting/hooking and modifying operating system API calls that supply system information.
Evidence: 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · ATT&CK page ↗
T1027Obfuscated Files or Information×1
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.
Evidence: 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · ATT&CK page ↗
T1055.004Process Injection: Asynchronous Procedure Call×1
Adversaries may inject malicious code into processes via the asynchronous procedure call (APC) queue in order to evade process-based defenses as well as possibly elevate privileges. APC injection is a method of executing arbitrary code in the address space of a separate live process.
Evidence: 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · ATT&CK page ↗
T1055.012Process Injection: Process Hollowing×1
Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses. Process hollowing is a method of executing arbitrary code in the address space of a separate live process.
Evidence: 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · ATT&CK page ↗
T1134.001Access Token Manipulation: Token Impersonation/Theft×1
Adversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access controls. For example, an adversary can duplicate an existing token using `DuplicateToken` or `DuplicateTokenEx`. The token can then be used with `ImpersonateLoggedOnUser` to allow the calling thread to impersonate a logged on user's security context, or with `SetThreadToken` to assign the impersonated token to a thread.
Evidence: 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · ATT&CK page ↗
Defense Impairment TA0112
T1685Disable or Modify Tools×1
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Evidence: 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · ATT&CK page ↗
Credential Access TA0006
T1003.002OS Credential Dumping: Security Account Manager×1
Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is stored. The SAM is a database file that contains local accounts for the host, typically those found with the <code>net user</code> command. Enumerating the SAM database requires SYSTEM level access.
Evidence: 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · ATT&CK page ↗
T1555.003Credentials from Password Stores: Credentials from Web Browsers×1
Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers.
Evidence: 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · ATT&CK page ↗
Command and Control TA0011
T1071.001Application Layer Protocol: Web Protocols×1
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · ATT&CK page ↗
Entries about Dell DBUtil_2_3.sys driver flaw, long patched, recorded only as the second vulnerable driver Cisco Talos observed the SPECTRE implant loading as its kernel read/write primitive. Not a new or in-window disclosure. (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Microsoft Internet Information Services×1
- Microsoft Windows×1
- MSI Afterburner RTCore64.sys driver flaw, long patched, recorded only as one of the two vulnerable drivers Cisco Talos observed the SPECTRE implant loading to obtain a kernel read/write primitive for unlinking EDR notification callbacks. Not a new or in-window disclosure.×1
- SPECTRE×1
- UAT-10147×1
Where this entity is cited
Source distribution
- blog.talosintelligence.com1 (100%)