CVE-2021-28310: high-severity vulnerability in Microsoft Windows 10 Version 1803
Win32k Elevation of Privilege Vulnerability
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply updates per vendor instructions.
A flaw in Windows' graphical interface system (Win32k) allows an attacker with basic user access to gain administrator privileges on the computer. This is dangerous because it lets someone take complete control of the system.
CWE-787 (out-of-bounds write) in Win32k kernel component allows local privilege escalation when a user with standard privileges crafts malicious input that triggers a memory write beyond buffer boundaries, enabling execution with elevated system permissions.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.