CVE-2021-33771
KEVmassPrivilege Escalation in Microsoft Windows Kernel Exploited in the Wild (CVE-2021-33771)
CISA: Microsoft Windows Kernel Privilege Escalation Vulnerability
CVE-2021-33771 is a high-severity (CVSS 3.1: 7.8) elevation-of-privilege flaw in the Windows kernel that allows a low-privileged user who can already execute code on a local machine to escalate to kernel-level (SYSTEM) privileges, with high impact on confidentiality, integrity and availability and no user interaction required. It is triggered locally, for example by running a malicious process or planted component on an affected system, and because it grants full SYSTEM rights it is typically chained with another flaw (such as a browser or document exploit) to escape a sandbox or complete an intrusion. Affected products span every mainstream Windows release current at disclosure: Windows 10 versions 1507, 1607, 1809, 1909, 2004, 20H2 and 21H1, Windows 8.1 and Windows RT 8.1, and Windows Server 2004, 2012 and 2016. The flaw was exploited before a patch existed; it was fixed in Microsoft's July 2021 Patch Tuesday (reported as 117 flaws including 9 zero-days, 4 actively exploited) and was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, with EPSS in the 95th percentile (~10% probability of exploitation within 30 days). Related coverage links the Windows zero-days patched in July 2021 to spyware operations by the Israeli surveillance vendor Candiru targeting journalists and activists, indicating targeted in-the-wild use rather than mass commodity exploitation.
What to do: Apply Microsoft's July 2021 (or later) cumulative security updates to all affected Windows 10, 8.1, RT 8.1 and Windows Server hosts and verify the kernel update is installed, prioritizing KEV-driven remediation. Given the reported use in targeted spyware campaigns against journalists and activists, hunt on systems that ran unpatched builds for signs of compromise, such as unexpected process creation by low-privileged users, novel persistence, or unusual outbound traffic.
| microsoft Windows 10 version 1507 | builds prior to the July 2021 security update |
| microsoft Windows 10 version 1607 | builds prior to the July 2021 security update |
| microsoft Windows 10 version 1809 | builds prior to the July 2021 security update |
| microsoft Windows 10 version 1909 | builds prior to the July 2021 security update |
| microsoft Windows 10 version 2004 | builds prior to the July 2021 security update |
| microsoft Windows 10 version 20H2 | builds prior to the July 2021 security update |
| microsoft Windows 10 version 21H1 | builds prior to the July 2021 security update |
| microsoft Windows 8.1 | builds prior to the July 2021 security update |
| microsoft Windows RT 8.1 | builds prior to the July 2021 security update |
| microsoft Windows Server 2004 | builds prior to the July 2021 security update |
| microsoft Windows Server 2012 | builds prior to the July 2021 security update |
| microsoft Windows Server 2016 | builds prior to the July 2021 security update |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows Kernel Elevation of Privilege Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 1909, windows 10 2004, windows 10 20h2, windows 10 21h1, windows 8.1, windows rt 8.1, windows server 2004, windows server 2012, windows server 2016
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H