ZeroHour

CVE-2021-33739

KEVmass1

Privilege Escalation in Microsoft Windows Desktop Window Manager (DWM) Core Library

CISA: Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability

CVSS 3.1
8.4 high
EPSS
7%p93
Published
()
KEV added
AI analysis

CVE-2021-33739 is an elevation-of-privilege vulnerability in the Microsoft Desktop Window Manager (DWM) Core Library, the component that composites the Windows graphical desktop. A local attacker who can already execute code on a vulnerable machine — for example via a malicious application, an Office payload, or a chained remote code execution bug — can exploit the flaw in DWM to gain elevated privileges on the system. Successful exploitation yields high-impact results (CVSS 8.4, high for confidentiality, integrity and availability), and the bug is typically used to break out of a low-privileged context or complete a full compromise chain. Affected systems are Windows 10 versions 1909, 2004, 20H2 and 21H1, and Windows Server versions 2004 and 20H2, prior to the June 2021 security updates. The flaw was one of six zero-days Microsoft confirmed as actively exploited in the June 2021 Patch Tuesday release; it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 and carries a 6.6% EPSS (93rd percentile), although no public PoC is known and ransomware use is undetermined.

What to do: Apply the June 2021 (or later) Windows cumulative updates on Windows 10 1909/2004/20H2/21H1 and Windows Server 2004/20H2, consistent with CISA's required action to apply vendor updates. Because this is a local privilege escalation, prioritize hosts where untrusted or multi-user code runs (VDI, RDS, kiosks, jump servers) and environments with KEV-mandated remediation deadlines. Verify patch status against the June 2021 release, since the bug was confirmed exploited in the wild.

Affected
microsoft Windows 101909 (pre-June 2021 Patch Tuesday updates)
microsoft Windows 102004 (pre-June 2021 Patch Tuesday updates)
microsoft Windows 1020H2 (pre-June 2021 Patch Tuesday updates)
microsoft Windows 1021H1 (pre-June 2021 Patch Tuesday updates)
microsoft Windows Server2004 (pre-June 2021 Patch Tuesday updates)
microsoft Windows Server20H2 (pre-June 2021 Patch Tuesday updates)
Estimated exposure
masshundreds of millions of endpoints (Windows 10's installed base exceeds 1 billion devices; builds 1909 through 21H1 were the dominant Windows 10 releases in… — Windows 10 runs on more than a billion devices worldwide and at the time of disclosure the 1909–21H1 releases accounted for the large majority of that installed base, with the Windows Server 2004/20H2 share comparatively small.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft DWM Core Library Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1909, windows 10 2004, windows 10 20h2, windows 10 21h1, windows server 2004, windows server 20h2
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news