CVE-2021-33744
published 2021-07-14CVE-2021-33744: Windows Secure Kernel Mode Security Feature Bypass Vulnerability
PriorityP430medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.79%
53.6th percentile
Windows Secure Kernel Mode Security Feature Bypass Vulnerability
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.2061 | 10.0.17763.2061 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.1679 | 10.0.18363.1679 |
| microsoft | windows_10_version_2004 | >= 10.0.0 < 10.0.19041.1110 | 10.0.19041.1110 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1110 | 10.0.19043.1110 |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.2061 | 10.0.17763.2061 |
| microsoft | windows_server_version_2004 | >= 10.0.0 < 10.0.19041.1110 | 10.0.19041.1110 |
| microsoft | windows_server_version_20h2 | >= 10.0.0 < 10.0.19042.1110 | 10.0.19042.1110 |
| msrc | windows_10_version_1809_for_x64-based_systems | — | — |
| msrc | windows_10_version_1909_for_x64-based_systems | — | — |
| msrc | windows_10_version_2004_for_x64-based_systems | — | — |
| msrc | windows_10_version_20h2_for_x64-based_systems | — | — |
| msrc | windows_10_version_21h1_for_x64-based_systems | — | — |
| msrc | windows_server_2019 | — | — |
| msrc | windows_server_version_2004 | — | — |
| msrc | windows_server_version_20h2 | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Windows up to Server 2019 Secure Kernel Mode privilege escalation
vuldb·2026-08-11·CVSS 6.7
CVE-2021-33744 [MEDIUM] Microsoft Windows up to Server 2019 Secure Kernel Mode privilege escalation
A vulnerability categorized as critical has been discovered in Microsoft Windows up to Server 2019. Affected by this vulnerability is an unknown functionality of the component Secure Kernel Mode. Such manipulation leads to privilege escalation.
This vulnerability is listed as CVE-2021-33744. The attack may be performed from remote. There is no available exploit.
It is advisable to implement a patch to correct this issue.
GHSA
GHSA-6qxh-x657-496f: Windows Secure Kernel Mode Security Feature Bypass Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-33744 [HIGH] CWE-269 GHSA-6qxh-x657-496f: Windows Secure Kernel Mode Security Feature Bypass Vulnerability
Windows Secure Kernel Mode Security Feature Bypass Vulnerability
Microsoft
Windows Secure Kernel Mode Security Feature Bypass Vulnerability
vendor_msrc·2021-07-13·CVSS 5.3
CVE-2021-33744 [MEDIUM] Windows Secure Kernel Mode Security Feature Bypass Vulnerability
Windows Secure Kernel Mode Security Feature Bypass Vulnerability
Windows Secure Kernel Mode: Windows Secure Kernel Mode
Microsoft: Microsoft
Impact: Security Feature Bypass
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5004244
Reference: https://support.microsoft.com/help/5004244
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5004245
Reference: https://support.microsoft.com/help/5004245
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5004237
Reference: https://support.microsoft.com/help/5004237
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-07-14
Published