Executive brief
A privilege escalation vulnerability exists in the Microsoft Windows Win32k component due to an out-of-bounds write (CWE-787). An attacker who successfully exploits this vulnerability could gain elevated system privileges. This vulnerability has been observed being exploited in the wild.
Affected products
- Microsoft Windows 10 1803, 1809, 1909, 2004, 20H2
- Microsoft Windows Server 1909, 2004, 20H2, 2019
Timeline
- 2021-04-13: disclosed: NVD Published Date
- 2021-04-13: patched: Microsoft released security updates
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Confirmed exploited in the wild per CISA KEV catalog entry date