⚠ Actively exploited in ransomware campaigns
This vulnerability is on the CISA Known Exploited Vulnerabilities list and has been used in known ransomware attacks. CISA required action: Apply updates per vendor instructions.. Due date: 2021-12-01.
Severity
7.8HIGH
No vector
EPSS
91.7%
top 0.32%
CISA KEV
KEVRansomware
Added 2021-11-17
Due 2021-12-01
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedOct 13
KEV addedNov 17
KEV dueDec 1
Latest updateMay 24
CISA Required Action: Apply updates per vendor instructions.

Description

Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability

Affected Packages26 packages

CVEListV5microsoft/windows_76.1.06.1.7601.25740
CVEListV5microsoft/windows_8.16.3.06.3.9600.20144
CVEListV5microsoft/windows_server_20126.2.06.2.9200.23490
CVEListV5microsoft/windows_server_201610.0.010.0.14393.4704
CVEListV5microsoft/windows_server_201910.0.010.0.17763.2237

🔴Vulnerability Details

4
GHSA
GHSA-qjf4-g2gg-w6pq: Win32k Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-40450, CVE-2021-413572022-05-24
Project0
The More You Know, The More You Know You Don’t Know - Project Zero2022-04-01
CVEList
Win32k Elevation of Privilege Vulnerability2021-10-13
VulnCheck
Microsoft Windows Win32k Privilege Escalation Vulnerability2021

📋Vendor Advisories

2
CISA
Microsoft Windows Win32k Privilege Escalation Vulnerability2021-11-17
Microsoft
Win32k Elevation of Privilege Vulnerability2021-10-12

🕵️Threat Intelligence

2
Qualys
Microsoft & Adobe Patch Tuesday (October 2021) – Microsoft 74 Vulnerabilities with 3 Critical, 4 Zero-Days. Adobe 10 Vulnerabilities2021-10-13
Qualys
Microsoft & Adobe Patch Tuesday (October 2021) – Microsoft 74 Vulnerabilities with 3 Critical, 4 Zero-Days. Adobe 10 Vulnerabilities | Qualys2021-10-13
CVE-2021-40449 (HIGH CVSS 7.8) | Win32k Elevation of Privilege Vulne | cvebase.io