ZeroHour

CVE-2021-33771

KEVmass

Privilege Escalation in Microsoft Windows Kernel Exploited in the Wild (CVE-2021-33771)

CISA: Microsoft Windows Kernel Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
10%p95
Published
()
KEV added
AI analysis

CVE-2021-33771 is a high-severity (CVSS 3.1: 7.8) elevation-of-privilege flaw in the Windows kernel that allows a low-privileged user who can already execute code on a local machine to escalate to kernel-level (SYSTEM) privileges, with high impact on confidentiality, integrity and availability and no user interaction required. It is triggered locally, for example by running a malicious process or planted component on an affected system, and because it grants full SYSTEM rights it is typically chained with another flaw (such as a browser or document exploit) to escape a sandbox or complete an intrusion. Affected products span every mainstream Windows release current at disclosure: Windows 10 versions 1507, 1607, 1809, 1909, 2004, 20H2 and 21H1, Windows 8.1 and Windows RT 8.1, and Windows Server 2004, 2012 and 2016. The flaw was exploited before a patch existed; it was fixed in Microsoft's July 2021 Patch Tuesday (reported as 117 flaws including 9 zero-days, 4 actively exploited) and was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, with EPSS in the 95th percentile (~10% probability of exploitation within 30 days). Related coverage links the Windows zero-days patched in July 2021 to spyware operations by the Israeli surveillance vendor Candiru targeting journalists and activists, indicating targeted in-the-wild use rather than mass commodity exploitation.

What to do: Apply Microsoft's July 2021 (or later) cumulative security updates to all affected Windows 10, 8.1, RT 8.1 and Windows Server hosts and verify the kernel update is installed, prioritizing KEV-driven remediation. Given the reported use in targeted spyware campaigns against journalists and activists, hunt on systems that ran unpatched builds for signs of compromise, such as unexpected process creation by low-privileged users, novel persistence, or unusual outbound traffic.

Affected
microsoft Windows 10 version 1507builds prior to the July 2021 security update
microsoft Windows 10 version 1607builds prior to the July 2021 security update
microsoft Windows 10 version 1809builds prior to the July 2021 security update
microsoft Windows 10 version 1909builds prior to the July 2021 security update
microsoft Windows 10 version 2004builds prior to the July 2021 security update
microsoft Windows 10 version 20H2builds prior to the July 2021 security update
microsoft Windows 10 version 21H1builds prior to the July 2021 security update
microsoft Windows 8.1builds prior to the July 2021 security update
microsoft Windows RT 8.1builds prior to the July 2021 security update
microsoft Windows Server 2004builds prior to the July 2021 security update
microsoft Windows Server 2012builds prior to the July 2021 security update
microsoft Windows Server 2016builds prior to the July 2021 security update
Estimated exposure
masshundreds of millions to 1 billion+ Windows devices and servers — Windows 10 ran on well over 1 billion devices at the time and the affected versions covered every then-current Windows 10 branch plus Windows 8.1/RT 8.1 and widely deployed Windows Server releases, so exposure is effectively the entire…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Kernel Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 1909, windows 10 2004, windows 10 20h2, windows 10 21h1, windows 8.1, windows rt 8.1, windows server 2004, windows server 2012, windows server 2016
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news