cbcvebase.
CVE-2021-1732
published 2021-02-25

CVE-2021-1732: Windows Win32k Elevation of Privilege Vulnerability

PriorityP189high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
EPSS
78.38%
99.5th percentile
Windows Win32k Elevation of Privilege Vulnerability

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_version_1803>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1809>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1909>= 10.0.0 < publicationpublication
microsoftwindows_10_version_2004>= 10.0.0 < publicationpublication
microsoftwindows_10_version_20h2>= 10.0.0 < publicationpublication
microsoftwindows_server_2019>= 10.0.0 < publicationpublication
microsoftwindows_server_version_2004>= 10.0.0 < publicationpublication
microsoftwindows_server_version_20h2>= 10.0.0 < publicationpublication
msrcwindows_10_version_1803_for_32-bit_systems
msrcwindows_10_version_1803_for_arm64-based_systems
msrcwindows_10_version_1803_for_x64-based_systems
msrcwindows_10_version_1809_for_32-bit_systems
msrcwindows_10_version_1809_for_arm64-based_systems
msrcwindows_10_version_1809_for_x64-based_systems
msrcwindows_10_version_1909_for_32-bit_systems
msrcwindows_10_version_1909_for_arm64-based_systems
msrcwindows_10_version_1909_for_x64-based_systems
msrcwindows_10_version_2004_for_32-bit_systems
msrcwindows_10_version_2004_for_arm64-based_systems
msrcwindows_10_version_2004_for_x64-based_systems
msrcwindows_10_version_20h2_for_32-bit_systems
msrcwindows_10_version_20h2_for_arm64-based_systems
msrcwindows_server_2019
msrcwindows_server_version_1909
msrcwindows_server_version_2004

Detection & IOCsextracted from sources · hover to see the quote

ip185.112.144.245
url185.112.144.45/a/data
domainadvb9fyxlf2v.com
registryHKLM\SYSTEM\CurrentControlSet\Services\{ac00-ac10}
filenamedbcode21mk.log
filenamesetupact64.log
path\??\C:\Windows\AppPatch\Acpsens.dll
path\??\C:\Windows\system32\sens.dll
path\??\C:\Windows\setupact64.log
urlhxxps://kmsauto[.]us/someone/start.ps1
domainkmsauto.us
filenamejavaw.exe
path%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\javaw.exe
filenamespooler.exe
filenameghost.exe
port135
port139
port445
  • CVE-2021-1732 exploitation targets win32kbase.sys via DirectComposition commands. Monitor for NtDCompositionCommitChannel and NtDCompositionProcessChannelBatchBuffer syscalls with anomalous SetResourceBufferProperty commands using DCOMPOSITION_EXPRESSION_TYPE=D2DVector2 and out-of-bounds propertyId values.
  • Exploit uses three DirectComposition command types in sequence: CreateResource, ReleaseResource, and SetResourceBufferProperty. Detecting unusual patterns of these three commands in rapid succession from a non-DWM process may indicate exploitation.
  • PurpleFox checks for specific hotfix KBs before selecting CVE-2021-1732 exploit. Absence of KB4601354, KB4601345, KB4601315, or KB4601319 on a Windows system indicates it is a viable target for this exploit chain.
  • PurpleFox installs a malicious sens.dll replacement via PendingFileRenameOperations. Monitor for PendingFileRenameOperations registry value pointing to non-standard paths replacing C:\Windows\system32\sens.dll.
  • FoxSocket backdoor uses WebSocket-based C2 with ECDH key exchange. The first key exchange message is AES-encrypted with a fixed length of 176 bytes; the second exchange has a fixed length of 304 bytes. These fixed-length encrypted WebSocket frames can be used as a network signature.
  • BlueSky ransomware exploiting CVE-2021-1732 drops payload as javaw.exe in the Startup folder. Alert on javaw.exe executing from %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\.
  • BITTER APT uses CVE-2021-1732 for privilege escalation as part of spearphishing campaigns delivering malicious RTF or Excel attachments. Correlate Win32k EoP with Office document execution chains.
  • ·The exploit requires heap grooming in dwm.exe to bypass two property checks (storageOffset and type) before the OOB write is triggered. Detection based solely on syscall monitoring may miss the exploitation if heap state is not also considered.
  • ·Microsoft may need to validate property counts for all DCOMPOSITION_EXPRESSION_TYPEs beyond D2DVector2 to fully close the vulnerability class; patching only D2DVector2 may leave other expression types exploitable.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat5.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.