ZeroHour

CVE-2021-28310

KEVmass1

Out-of-Bounds Write in Microsoft Win32k Allows Local Privilege Escalation on Windows 10

CISA: Microsoft Win32k Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
8%p95
Published
()
KEV added
AI analysis

CVE-2021-28310 is an elevation-of-privilege flaw caused by an out-of-bounds write (CWE-787) in the Windows Win32k kernel component. A local attacker who can already execute low-privileged code on a vulnerable system can trigger the memory corruption bug to run arbitrary code in kernel mode, with no user interaction required. Successful exploitation grants SYSTEM/kernel-level control of the host, typically as a follow-on step after an attacker has gained an initial foothold, rather than a remote-entry vector. Windows 10 versions 1803, 1809, 1909, 2004 and 20H2, plus the corresponding Windows Server versions 1909, 2004, 2019 and 20H2, are affected. The flaw was fixed in Microsoft's April 2021 security updates and has been actively exploited in the wild — CISA added it to the KEV catalog on 2021-11-03, and its EPSS of 8.3% (95th percentile) signals elevated exploitation risk.

What to do: Apply the April 2021 (or later) Windows cumulative security updates to all affected Windows 10 and Windows Server systems, prioritizing hosts where untrusted or low-privileged users can run code, such as terminal/RDS servers, VDI and shared workstations. Because this flaw is in the CISA KEV catalog, applying vendor updates is a required action for federal and regulated environments; verify remediation by confirming the installed OS build includes the April 2021 patch. For systems that cannot be patched promptly, limit local code execution by untrusted users and monitor for post-exploitation privilege-escalation behavior.

Affected
Microsoft Windows 101803
Microsoft Windows 101809
Microsoft Windows 101909
Microsoft Windows 102004
Microsoft Windows 1020H2
Microsoft Windows Server1909
Microsoft Windows Server2004
Microsoft Windows Server2019
Microsoft Windows Server20H2
Estimated exposure
masshundreds of millions of Windows 10 and Windows Server endpoints worldwide — The affected Windows 10 servicing branches (1803 through 20H2) and Server 2019-era releases made up the bulk of in-support Windows deployments at the time of disclosure, when the Windows 10 installed base exceeded one billion devices.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Win32k Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Win32k
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1803, windows 10 1809, windows 10 1909, windows 10 2004, windows 10 20h2, windows server 1909, windows server 2004, windows server 2019, windows server 20h2
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news