Vulnerability record · CVE-2021-1732 · published 25 February 2021
CVE-2021-1732: Microsoft Windows Win32k out-of-bounds write privilege escalation
Microsoft · Windows 10 1803
CVE-2021-1732 is an out-of-bounds write (CWE-787) in the Windows Win32k component that allows a local user to elevate privileges. It affects multiple Windows 10 and Windows Server builds, and Microsoft released a patch in February 2021. Because it is a kernel-level elevation flaw with public exploit code and confirmed in-the-wild use, it is a serious risk on unpatched systems.
Description
Windows Win32k Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a patched but actively exploited local privilege escalation flaw in CISA KEV with known ransomware use and very high EPSS, though it requires an existing local foothold.
What it is
CVE-2021-1732 is an out-of-bounds write (CWE-787) in the Windows Win32k component that allows a local user to elevate privileges. It affects multiple Windows 10 and Windows Server builds, and Microsoft released a patch in February 2021. Because it is a kernel-level elevation flaw with public exploit code and confirmed in-the-wild use, it is a serious risk on unpatched systems.
Impact
A local attacker who can run code on a target can exploit the out-of-bounds write to gain SYSTEM-level privileges. That access can then be used to disable defenses, install persistence, or move laterally.
Attack surface
The flaw is reached locally through the Win32k subsystem, requiring the attacker to already have code execution or an interactive session on the host. No user interaction is needed beyond that local access, and the CVSS vector (AV:L/PR:L/UI:N) confirms a low-privileged local user is sufficient.
Exploitation
CVE-2021-1732 is listed in CISA KEV with a due date of 2021-11-17 and is flagged for known ransomware campaign use; EPSS is 0.78376 (99.6th percentile). Public exploit code is referenced on Packet Storm, so exploitation is both practical and observed.
What to do
- Apply the Microsoft security update for CVE-2021-1732 on all affected Windows 10 and Windows Server builds.
- Prioritize patching internet-facing and high-value systems, and verify patch status across the listed product versions.
- Restrict local interactive logon and code execution to trusted users, since the flaw requires a local foothold.
- Enable and monitor endpoint detection for privilege escalation and suspicious Win32k activity.
- Review KEV remediation tracking to confirm all affected assets meet the required action.
Detection
- Monitor for processes spawning with SYSTEM integrity from non-system parent processes, especially after user-level execution.
- Look for exploitation artifacts tied to Win32k ConsoleControl offset confusion, such as unusual handle or object manipulation.
- Alert on known exploit tooling or payloads associated with CVE-2021-1732 appearing on endpoints.
- Correlate local privilege escalation events with subsequent defense evasion, persistence, or ransomware precursor activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-1732 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Win32k Privilege Escalation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/161880/Win32k-ConsoleControl-Offset-Confusion.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/166169/Win32k-ConsoleControl-Offset-Confusion-Privilege-Escalation.html | ExploitThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-1732 | PatchVendor Advisory |
| http://packetstormsecurity.com/files/161880/Win32k-ConsoleControl-Offset-Confusion.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/166169/Win32k-ConsoleControl-Offset-Confusion-Privilege-Escalation.html | ExploitThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-1732 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-1732 | US Government Resource |
Track CVE-2021-1732 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-1732), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.