7.8
CVE-2021-1732
- EPSS 77.76%
- Veröffentlicht 25.02.2021 23:15:13
- Zuletzt bearbeitet 12.08.2026 05:17:32
- CVE-Watchlists
- Unerledigt
Windows Win32k Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 1803 Version-
Microsoft ≫ Windows 10 1809 Version-
Microsoft ≫ Windows 10 1909 Version-
Microsoft ≫ Windows 10 2004 Version-
Microsoft ≫ Windows 10 20h2 Version-
Microsoft ≫ Windows Server 1909 Version-
Microsoft ≫ Windows Server 2004 Version-
Microsoft ≫ Windows Server 2019 Version-
Microsoft ≫ Windows Server 20h2 Version-
03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog
Microsoft Win32k Privilege Escalation Vulnerability
SchwachstelleMicrosoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 77.76% | 0.995 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| Microsoft | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
http://packetstormsecurity.com/files/161880/Win32k-ConsoleControl-Offset-Confusion.html
http://packetstormsecurity.com/files/166169/Win32k-ConsoleControl-Offset-Confusion-Privilege-Escalation.html
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-1732
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-1732