cbcvebase.
CVE-2021-28310
published 2021-04-13

CVE-2021-28310: Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
EPSS
8.33%
94.3th percentile
Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_version_1803>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1809>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1909>= 10.0.0 < publicationpublication
microsoftwindows_10_version_2004>= 10.0.0 < publicationpublication
microsoftwindows_10_version_20h2>= 10.0.0 < publicationpublication
microsoftwindows_server_2019>= 10.0.0 < publicationpublication
microsoftwindows_server_version_2004>= 10.0.0 < publicationpublication
microsoftwindows_server_version_20h2>= 10.0.0 < publicationpublication
msrcwindows_10_version_1803_for_32-bit_systems
msrcwindows_10_version_1803_for_arm64-based_systems
msrcwindows_10_version_1803_for_x64-based_systems
msrcwindows_10_version_1809_for_32-bit_systems
msrcwindows_10_version_1809_for_arm64-based_systems
msrcwindows_10_version_1809_for_x64-based_systems
msrcwindows_10_version_1909_for_32-bit_systems
msrcwindows_10_version_1909_for_arm64-based_systems
msrcwindows_10_version_1909_for_x64-based_systems
msrcwindows_10_version_2004_for_32-bit_systems
msrcwindows_10_version_2004_for_arm64-based_systems
msrcwindows_10_version_2004_for_x64-based_systems
msrcwindows_10_version_20h2_for_32-bit_systems
msrcwindows_10_version_20h2_for_arm64-based_systems
msrcwindows_10_version_20h2_for_x64-based_systems
msrcwindows_server_2019
msrcwindows_server_version_1909

Detection & IOCsextracted from sources · hover to see the quote

domainhelpdesk[.]autodefragapp[.]com
ip99[.]83[.]154[.]118
domainmswsceventlog[.]net
domainolmajhnservice[.]com
urlhxxp[:]//olmajhnservice[.]/nxl/nx
pathC:\$Utf
filenameRdxFactory.exe
filenamePassport Fee Dues.xlsx
filenameList of Numbers to be verified.xlsx
filenameASP AVIJIT DAS.doc
filenameAddl SP Hafizur Rahman.doc
filenameAddl SP Hafizur Rahman.xlsx
filenameRegistered Cases List.xlsx
  • Monitor for NtDCompositionCommitChannel and NtDCompositionProcessChannelBatchBuffer syscalls with anomalous DirectComposition command sequences (CreateResource, ReleaseResource, SetResourceBufferProperty) that may indicate heap-grooming for OOB write exploitation in dwm.exe.
  • Detect SetResourceBufferProperty commands with DCOMPOSITION_EXPRESSION_TYPE set to D2DVector2 (_D2DVector2) combined with an out-of-bounds propertyId, as this is the specific expression type abused to trigger the OOB write in CPropertySet::UpdateProperty within dwmcore.dll.
  • Hunt for scheduled tasks named 'Rdx' and 'RdxFac' configured to run every five minutes, and creation of the folder 'RdxFact' in the Windows tasks folder — indicators of the Bitter APT ZxxZ trojan dropper stage.
  • Detect RdxFactory.exe being written to the public user profile's music folder via cURL, as this is the ZxxZ trojan downloader dropped by the Bitter APT Excel maldoc infection chain.
  • Detect Equation Editor (EQNEDT32.EXE) spawning child processes or making outbound network connections, particularly to download payloads into C:\$Utf, as part of CVE-2017-11882/CVE-2018-0798/CVE-2018-0802 exploitation used alongside CVE-2021-28310.
  • ·The vulnerability exists in dwmcore.dll (user-mode, dwm.exe process) due to missing bounds check on propertyId in CPropertySet::UpdateProperty; the kernel-mode version in win32kbase.sys does have the check, but it can be bypassed via the AddProperty inconsistency.
  • ·The C2 IP 99.83.154.118 is a legitimate AWS Global Accelerator address used by the actor to redirect traffic to their actual C2, making IP-based blocking unreliable; domain-based detection is preferred.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
cvelistv57.8HIGH
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.