Vulnerability record · CVE-2021-33739 · published 8 June 2021
CVE-2021-33739: Microsoft DWM Core Library elevation of privilege
Microsoft · Windows 10 1909
CVE-2021-33739 is an elevation of privilege flaw in the Microsoft Desktop Window Manager (DWM) Core Library affecting several Windows 10 and Windows Server builds. The record gives no root-cause detail beyond 'insufficient information', but the local vector and high confidentiality, integrity and availability impact mean a successful exploit gives full control of the affected host. It matters because it is listed in CISA's Known Exploited Vulnerabilities catalog, so it has been used in real attacks.
Description
Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is confirmed exploited in the wild per CISA KEV and yields full host compromise, though it requires a local foothold rather than remote access.
What it is
CVE-2021-33739 is an elevation of privilege flaw in the Microsoft Desktop Window Manager (DWM) Core Library affecting several Windows 10 and Windows Server builds. The record gives no root-cause detail beyond 'insufficient information', but the local vector and high confidentiality, integrity and availability impact mean a successful exploit gives full control of the affected host. It matters because it is listed in CISA's Known Exploited Vulnerabilities catalog, so it has been used in real attacks.
Impact
An attacker who runs code on the machine can escalate to SYSTEM or kernel-level privileges, gaining full control of the host. That access can be used to disable defenses, move laterally or deploy further payloads.
Attack surface
The vector is local (AV:L) with no privileges (PR:N) and no user interaction (UI:N), so the attacker must already have a foothold or the ability to run code on the target. It is not remotely reachable and does not require a victim to open a file or click anything.
Exploitation
CISA added it to the KEV catalog on 2021-11-03 with a 2021-11-17 remediation due date, confirming exploitation in the wild. EPSS gives a 30-day probability of about 6.6 percent (93rd percentile), and no ransomware campaign use is recorded.
What to do
- Apply the Microsoft security update for CVE-2021-33739 on all affected Windows 10 and Windows Server builds; this is the primary fix.
- Prioritize patching of internet-facing and high-value endpoints, since the flaw is known to be exploited.
- Restrict who can run code locally and enforce least privilege to reduce the foothold an attacker needs.
- Monitor for and block known post-exploitation tooling that relies on local privilege escalation.
- Verify patch coverage against the affected build list (Windows 10 1909, 2004, 20H2, 21H1 and Windows Server 2004, 20H2).
Detection
- Hunt for unexpected processes gaining SYSTEM or kernel-level tokens shortly after a low-privilege process starts.
- Monitor for suspicious interaction with dwm.exe or DWM Core Library components from non-standard parent processes.
- Alert on known local privilege escalation exploit binaries or scripts executing on unpatched hosts.
- Correlate endpoint telemetry for privilege changes with the presence of unpatched Windows builds.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-33739 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-33739 | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-33739 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-33739 | US Government Resource |
Track CVE-2021-33739 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-33739), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.