Executive brief
Microsoft Win32k contains an elevation of privilege vulnerability that allows a local attacker to gain system-level privileges. The flaw is caused by insufficient restrictions within the Win32k kernel-mode driver. This vulnerability has been observed being exploited in the wild.
Affected products
- Microsoft Windows 10 1809, 1909, 2004, 20H2, 21H1
- Microsoft Windows 11 21H2
- Microsoft Windows Server 2004, 20H2, 2019, 2022
Timeline
- 2021-10-19: disclosed: Initial analysis by NIST and Microsoft advisory release
- 2022-04-25: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog