⚠ Actively exploited
Added to CISA KEV on 2022-04-25. Federal agencies required to patch by 2022-05-16. Required action: Apply updates per vendor instructions..

CVE-2021-40450

Severity
7.8HIGH
No vector
EPSS
5.6%
top 9.69%
CISA KEV
KEV
Added 2022-04-25
Due 2022-05-16
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedOct 13
KEV addedApr 25
KEV dueMay 16
Latest updateMay 24
CISA Required Action: Apply updates per vendor instructions.

Description

Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability

Affected Packages11 packages

CVEListV5microsoft/windows_server_201910.0.010.0.17763.2237
CVEListV5microsoft/windows_server_202210.0.010.0.20348.288
CVEListV5microsoft/windows_10_version_180910.0.010.0.17763.2237
CVEListV5microsoft/windows_10_version_190910.0.010.0.18363.1854
CVEListV5microsoft/windows_10_version_200410.0.010.0.19041.1288

🔴Vulnerability Details

3
GHSA
GHSA-v7qc-rhmv-f6j4: Win32k Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-40449, CVE-2021-413572022-05-24
CVEList
Win32k Elevation of Privilege Vulnerability2021-10-13
VulnCheck
Microsoft Win32k Privilege Escalation Vulnerability2021

📋Vendor Advisories

2
CISA
Microsoft Win32k Privilege Escalation Vulnerability2022-04-25
Microsoft
Win32k Elevation of Privilege Vulnerability2021-10-12
CVE-2021-40450 (HIGH CVSS 7.8) | Win32k Elevation of Privilege Vulne | cvebase.io