Executive brief
Microsoft Win32k contains an elevation of privilege vulnerability that allows a local attacker to gain system-level privileges. The vulnerability is distinct from CVE-2021-40449 and CVE-2021-40450 and has been observed being exploited in the wild.
Affected products
- Microsoft Windows 10 2004, 20H2, 21H1
- Microsoft Windows 11 21H2
- Microsoft Windows Server 2022 -
- Microsoft Windows Server 2004, 20H2
Timeline
- 2021-10-12: disclosed: NVD Published Date
- 2022-04-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-05-16: other: CISA KEV due date for remediation