Junglewise Threat Intelligence

CVE-2021-41357: Microsoft Win32k Privilege Escalation Vulnerability

CVE-2021-41357 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-04-25

Technologies: Microsoft Windows 11, Microsoft Windows 10, Microsoft Windows Server, Microsoft Windows Server 2022, Microsoft Win32K. Vendors: Microsoft.

Executive brief

Microsoft Win32k contains an elevation of privilege vulnerability that allows a local attacker to gain system-level privileges. The vulnerability is distinct from CVE-2021-40449 and CVE-2021-40450 and has been observed being exploited in the wild.

Affected products

  • Microsoft Windows 10 2004, 20H2, 21H1
  • Microsoft Windows 11 21H2
  • Microsoft Windows Server 2022 -
  • Microsoft Windows Server 2004, 20H2

Timeline

  • 2021-10-12: disclosed: NVD Published Date
  • 2022-04-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-05-16: other: CISA KEV due date for remediation

Related threats