CVE-2021-40450
KEVmassLocal Privilege Escalation in Microsoft Win32k (Windows 10/11 and Windows Server)
CISA: Microsoft Win32k Privilege Escalation Vulnerability
CVE-2021-40450 is an elevation-of-privilege vulnerability in Win32k, the Windows kernel-mode graphics/window-manager subsystem, affecting Windows 10 (builds 1809 through 21H1), Windows 11 21H2, and Windows Server 2019, 2004, 20H2, and 2022. It is triggered locally: per the CVSS vector (AV:L/PR:L/UI:N), an attacker must already be able to execute code on the target as a low-privileged user, with no user interaction required, and then abuses the Win32k flaw to escalate. Successful exploitation yields SYSTEM-level privileges, giving full control of the host (reading or modifying any data, installing software, disabling security controls), and such flaws are commonly chained with an initial remote-code-execution or phishing foothold to fully compromise a machine. Any organization or individual running the affected Windows builds is exposed in principle, though practical risk concentrates on hosts where an attacker can first gain a local foothold. The flaw was addressed in Microsoft's October 2021 Patch Tuesday; it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-25, confirming in-the-wild exploitation (no public PoC is known, EPSS estimates roughly 2.1% probability of exploitation in the next 30 days, and any ransomware association is unconfirmed).
What to do: Apply Microsoft's October 2021 security updates (per vendor instructions) to all affected Windows 10, Windows 11, and Windows Server hosts, prioritizing endpoints exposed to untrusted users and servers where an attacker could chain this elevation with a remote-code-execution or phishing foothold. Because the flaw is KEV-listed with confirmed in-the-wild exploitation, verify installed patch/build levels across the estate and check hosts with any indicators of compromise for local privilege-escalation activity; if patching is delayed, limit local code execution by untrusted users and monitor for suspicious SYSTEM-level process activity.
| Microsoft Windows 10 | 1809, 1909, 2004, 20H2, 21H1 |
| Microsoft Windows 11 | 21H2 |
| Microsoft Windows Server | 2019, 2004, 20H2, 2022 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Win32k Elevation of Privilege Vulnerability
- Affected
- Microsoft Win32k
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1809, windows 10 1909, windows 10 2004, windows 10 20h2, windows 10 21h1, windows 11 21h2, windows server 2004, windows server 2019, windows server 2022, windows server 20h2
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H