← back
CVE-2021-40449

Win32k Elevation of Privilege Vulnerability

CVSS 7.8 HIGHEPSS 73.4%● KEVCWE-416
In short

A flaw in Windows' graphical interface system (Win32k) allows an attacker who has already gained basic access to a computer to gain full administrative control. This happens because the system doesn't properly manage memory, leaving it vulnerable to manipulation.

Technical detail

Use-after-free vulnerability in Win32k kernel driver enabling local privilege escalation; requires prior code execution with limited privileges. Attacker can manipulate freed memory objects to execute arbitrary code in kernel context, achieving SYSTEM-level access.

Summary generated and translated by AI from the official description.
Win32k Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →