ZeroHour

CVE-2021-1732

KEV ransomware PoC ×2mass

Out-of-Bounds Write Local Privilege Escalation in Microsoft Win32k (CVE-2021-1732)

CISA: Microsoft Win32k Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
78%p100
Published
()
KEV added
AI analysis

CVE-2021-1732 is a local elevation-of-privilege vulnerability (CWE-787, out-of-bounds write) in Microsoft's Win32k kernel driver, publicly characterized as an "offset confusion" in the Win32k ConsoleControl routine. It is triggered locally: a process with only low privileges can invoke the vulnerable Win32k functionality without any user interaction, causing a user-supplied offset/pointer to be mishandled in kernel mode and memory to be written out of bounds. An attacker who successfully exploits the flaw can execute code in the kernel and elevate to SYSTEM, gaining full control of the host — which makes it a valuable second-stage link in malware and ransomware chains. Any system running the affected Windows 10 releases (1803, 1809, 1909, 2004, 20H2) or Windows Server 2019/1909/2004/20H2 is exposed, though exploitation requires the attacker to already run code locally on the target. The flaw was fixed in Microsoft's February 2021 Patch Tuesday updates, was added to CISA's KEV catalog on 2021-11-03 with known ransomware use, and carries a very high EPSS score (78.4%, 100th percentile), indicating sustained exploitation pressure.

What to do: Apply Microsoft's February 2021 (or later) Windows cumulative security updates to all affected Windows 10 and Windows Server systems, per vendor instructions — CISA's KEV listing requires federal agencies to patch. Prioritize hosts exposed to untrusted local users or already compromised by malware (e.g., ransomware or Raspberry Robin activity, which has used chained Windows LPEs), and hunt on unpatched hosts for signs of post-exploitation privilege escalation to SYSTEM.

Affected
Microsoft Windows 101803
Microsoft Windows 101809
Microsoft Windows 101909
Microsoft Windows 102004
Microsoft Windows 1020H2
Microsoft Windows Server 19091909
Microsoft Windows Server 20042004
Microsoft Windows Server 20192019
Microsoft Windows Server 20H220H2
Estimated exposure
mass≈1 billion+ Windows devices (the listed builds spanned the mainstream Windows 10/Server install base) — Windows 10 runs on well over a billion devices and the 1803–20H2 workstation builds plus Windows Server 2019/1909/2004/20H2 made up the bulk of active Windows deployments when the bug was patched in February 2021, so any unpatched machine…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Win32k Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Win32k
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1803, windows 10 1809, windows 10 1909, windows 10 2004, windows 10 20h2, windows server 1909, windows server 2004, windows server 2019, windows server 20h2
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news