Executive brief
A use-after-free vulnerability in the Windows Win32k component (specifically involving NtGdiResetDC) allows an authenticated local attacker to escalate privileges. The vulnerability has been observed being exploited in the wild.
Affected products
- Microsoft Windows 10 up to (excluding) 10.0.10240.19086
- Microsoft Windows 11 up to (excluding) 10.0.22000.258
- Microsoft Windows Server 2022 up to (excluding) 10.0.20348.288
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1
- Microsoft Windows Server 2008
- Microsoft Windows Server 2012
- Microsoft Windows Server 2016
- Microsoft Windows Server 2019
Timeline
- 2021-11-17: disclosed
- 2021-11-17: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-17: patched