Junglewise Threat Intelligence

CVE-2021-33739: Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability

CVE-2021-33739 · Severity: critical · CVSS 8.4 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Windows 10, Microsoft Windows, Microsoft Windows Server 2016. Vendors: Microsoft.

Executive brief

The Microsoft Desktop Window Manager (DWM) Core Library contains a privilege escalation vulnerability that allows a local attacker to gain elevated system privileges. The vulnerability has been observed being exploited in the wild.

Affected products

  • Microsoft Windows 10 1909, 2004, 20H2, 21H1
  • Microsoft Windows Server 2016 2004, 20H2

Timeline

  • 2021-06-08: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats