Executive brief
A privilege escalation vulnerability exists in the Microsoft Win32k component due to an out-of-bounds write (CWE-787) or offset confusion. An attacker with local access can exploit this to gain elevated system privileges.
Affected products
- Microsoft Windows 10 1803, 1809, 1909, 2004, 20H2
- Microsoft Windows Server 1909, 2004, 20H2, 2019
Timeline
- 2021-02-24: patched: Microsoft released security updates to address the vulnerability.
- 2021-11-03: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
- 2021-11-03: disclosed: Publicly disclosed and published to NVD.
- 2021-11-03: exploited: Confirmed as exploited in the wild per CISA KEV catalog.