cbcvebase.
CVE-2021-40449
published 2021-10-13

CVE-2021-40449: Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2021-12-01
Exploited in the wild
EPSS
73.38%
99.4th percentile
Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_version_1507>= 10.0.0 < 10.0.10240.1908610.0.10240.19086
microsoftwindows_10_version_1607>= 10.0.0 < 10.0.14393.470410.0.14393.4704
microsoftwindows_10_version_1809>= 10.0.0 < 10.0.17763.223710.0.17763.2237
microsoftwindows_10_version_1909>= 10.0.0 < 10.0.18363.185410.0.18363.1854
microsoftwindows_10_version_2004>= 10.0.0 < 10.0.19041.128810.0.19041.1288
microsoftwindows_10_version_20h2>= 10.0.0 < 10.0.19041.128810.0.19041.1288
microsoftwindows_10_version_21h1>= 10.0.0 < 10.0.19041.128810.0.19041.1288
microsoftwindows_11_version_21h2>= 10.0.0 < 10.0.22000.25810.0.22000.258
microsoftwindows_7>= 6.1.0 < 6.1.7601.257406.1.7601.25740
microsoftwindows_7_service_pack_1>= 6.1.0 < 6.1.7601.257406.1.7601.25740
microsoftwindows_8.1>= 6.3.0 < 6.3.9600.201446.3.9600.20144
microsoftwindows_server_2008_r2_service_pack_1>= 6.0.0 < 6.1.7601.257406.1.7601.25740
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.0 < 6.1.7601.257406.1.7601.25740
microsoftwindows_server_2008_service_pack_2>= 6.0.0 < 6.0.6003.212516.0.6003.21251
microsoftwindows_server_2012>= 6.2.0 < 6.2.9200.234906.2.9200.23490
microsoftwindows_server_2012_r2>= 6.3.0 < 6.3.9600.201446.3.9600.20144
microsoftwindows_server_2016>= 10.0.0 < 10.0.14393.470410.0.14393.4704
microsoftwindows_server_2019>= 10.0.0 < 10.0.17763.223710.0.17763.2237
microsoftwindows_server_2022>= 10.0.0 < 10.0.20348.28810.0.20348.288
microsoftwindows_server_version_2004>= 10.0.0 < 10.0.19041.128810.0.19041.1288
microsoftwindows_server_version_20h2>= 10.0.0 < 10.0.19042.128810.0.19042.1288
msrcwindows_10
msrcwindows_10_version_1607
msrcwindows_10_version_1809
msrcwindows_10_version_1909

Detection & IOCsextracted from sources · hover to see the quote

domainwatch-smcsvc[.]com
domainleotolstoys[.]com
domainppng.io
filenameCiscoSparkLauncher.dll
filenameCiscoCollabHost.exe
filenamefltlib.dll
filenameattach.dat
path%AppData%\Cisco\Plugins\X86\bin\etc\Update
  • The exploit leverages GDI palette objects to achieve a desired memory state and uses a single kernel function call to build a read/write kernel memory primitive. Detect anomalous GDI palette object allocation patterns from Medium IL processes.
  • MysterySnail RAT copies cmd.exe to the temp folder under a different name before launching an interactive shell (command ID 0x1F4). Monitor for cmd.exe copies in %TEMP% with non-standard names spawned by suspicious parent processes.
  • The intermediary backdoor (CiscoSparkLauncher.dll) stores Windows API function information in an external XOR-encrypted file (log\MYFC.log) loaded at runtime, rather than in the DLL's import table. Absence of standard API imports combined with an external encrypted log file is a strong behavioral indicator.
  • The intermediary backdoor communicates via the legitimate piping-server (ppng.io) to relay C2 commands, abusing a public open-source project. Monitor for unexpected outbound HTTPS connections to ppng.io from enterprise endpoints.
  • New MysterySnail RAT persists as a Windows service and uses DLL sideloading via a legitimate executable (sophosfilesubmitter.exe or CiscoCollabHost.exe). Monitor for legitimate vendor executables loading unexpected DLLs (fltlib.dll, CiscoSparkLauncher.dll) from non-standard paths.
  • The typo 'ExplorerMoudleDll.dll' (not 'ExplorerModuleDll.dll') is a persistent artifact across MysterySnail RAT versions from 2021 through 2025 and can be used as a YARA/filesystem hunting string.
  • ·The exploit supports a specific, limited set of Windows versions (Vista through Server 2019 build 17763). Systems outside this list or with the October 2021 Patch Tuesday update applied are not vulnerable to CVE-2021-40449 via this exploit. Attackers fall back to BYOVD when the patch is present.
  • ·The information disclosure portion of the CVE-2021-40449 exploit chain (kernel module base address leakage) was assessed by Microsoft as not bypassing a security boundary and was therefore NOT patched. Kernel ASLR bypass via NtQuerySystemInformation/EnumDeviceDrivers from Medium IL remains available post-patch.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
cvelistv57.8HIGH
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.