CVE-2021-28310highunder attackCWE-787

CVE-2021-28310: high-severity vulnerability in Microsoft Windows 10 Version 1803

Win32k Elevation of Privilege Vulnerability

Published · Updated

71Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 7.8epss 8.3%
from disclosure to weapon1 days
Published on NVDApr 13
1st PoC+1d
CISA KEV+204d
exploitation probability
8.3%top 5% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2021-11-17

Apply updates per vendor instructions.

In short

A flaw in Windows' graphical interface system (Win32k) allows an attacker with basic user access to gain administrator privileges on the computer. This is dangerous because it lets someone take complete control of the system.

Technical detail

CWE-787 (out-of-bounds write) in Win32k kernel component allows local privilege escalation when a user with standard privileges crafts malicious input that triggers a memory write beyond buffer boundaries, enabling execution with elevated system permissions.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Win32k Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.