CVE-2021-28310
KEVmass1Out-of-Bounds Write in Microsoft Win32k Allows Local Privilege Escalation on Windows 10
CISA: Microsoft Win32k Privilege Escalation Vulnerability
CVE-2021-28310 is an elevation-of-privilege flaw caused by an out-of-bounds write (CWE-787) in the Windows Win32k kernel component. A local attacker who can already execute low-privileged code on a vulnerable system can trigger the memory corruption bug to run arbitrary code in kernel mode, with no user interaction required. Successful exploitation grants SYSTEM/kernel-level control of the host, typically as a follow-on step after an attacker has gained an initial foothold, rather than a remote-entry vector. Windows 10 versions 1803, 1809, 1909, 2004 and 20H2, plus the corresponding Windows Server versions 1909, 2004, 2019 and 20H2, are affected. The flaw was fixed in Microsoft's April 2021 security updates and has been actively exploited in the wild — CISA added it to the KEV catalog on 2021-11-03, and its EPSS of 8.3% (95th percentile) signals elevated exploitation risk.
What to do: Apply the April 2021 (or later) Windows cumulative security updates to all affected Windows 10 and Windows Server systems, prioritizing hosts where untrusted or low-privileged users can run code, such as terminal/RDS servers, VDI and shared workstations. Because this flaw is in the CISA KEV catalog, applying vendor updates is a required action for federal and regulated environments; verify remediation by confirming the installed OS build includes the April 2021 patch. For systems that cannot be patched promptly, limit local code execution by untrusted users and monitor for post-exploitation privilege-escalation behavior.
| Microsoft Windows 10 | 1803 |
| Microsoft Windows 10 | 1809 |
| Microsoft Windows 10 | 1909 |
| Microsoft Windows 10 | 2004 |
| Microsoft Windows 10 | 20H2 |
| Microsoft Windows Server | 1909 |
| Microsoft Windows Server | 2004 |
| Microsoft Windows Server | 2019 |
| Microsoft Windows Server | 20H2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Win32k Elevation of Privilege Vulnerability
- Affected
- Microsoft Win32k
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1803, windows 10 1809, windows 10 1909, windows 10 2004, windows 10 20h2, windows server 1909, windows server 2004, windows server 2019, windows server 20h2
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H