Executive brief
A privilege escalation vulnerability exists in the Microsoft Windows Kernel due to improper restriction of operations within the bounds of a memory buffer (CWE-119). An attacker who successfully exploits this vulnerability could gain elevated system privileges.
Affected products
- Microsoft Windows 10 1507, 1607, 1809, 1909, 2004, 20H2, 21H1
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1
- Microsoft Windows RT 8.1
- Microsoft Windows Server 2008 SP2, R2 SP1
- Microsoft Windows Server 2012 Base, R2
- Microsoft Windows Server 2016
- Microsoft Windows Server 2019
- Microsoft Windows Server 2004
- Microsoft Windows Server 20H2
Timeline
- 2021-11-03: advisory: Microsoft published the security advisory.
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.
- 2021-11-03: exploited: Vulnerability reported as being exploited in the wild.