← Vulnerability feed

Vulnerability record · CVE-2021-33739 · published 8 June 2021

CVE-2021-33739: Microsoft DWM Core Library elevation of privilege

Microsoft · Windows 10 1909

CVE-2021-33739 is an elevation of privilege flaw in the Microsoft Desktop Window Manager (DWM) Core Library affecting several Windows 10 and Windows Server builds. The record gives no root-cause detail beyond 'insufficient information', but the local vector and high confidentiality, integrity and availability impact mean a successful exploit gives full control of the affected host. It matters because it is listed in CISA's Known Exploited Vulnerabilities catalog, so it has been used in real attacks.

8.4 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 6.6% · top 6.4%
8.4CVSS 3.1 base score, v2 4.6
6.6%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
6Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Microsoft DWM Core Library Elevation of Privilege Vulnerability

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityIt is confirmed exploited in the wild per CISA KEV and yields full host compromise, though it requires a local foothold rather than remote access.

What it is

CVE-2021-33739 is an elevation of privilege flaw in the Microsoft Desktop Window Manager (DWM) Core Library affecting several Windows 10 and Windows Server builds. The record gives no root-cause detail beyond 'insufficient information', but the local vector and high confidentiality, integrity and availability impact mean a successful exploit gives full control of the affected host. It matters because it is listed in CISA's Known Exploited Vulnerabilities catalog, so it has been used in real attacks.

Impact

An attacker who runs code on the machine can escalate to SYSTEM or kernel-level privileges, gaining full control of the host. That access can be used to disable defenses, move laterally or deploy further payloads.

Attack surface

The vector is local (AV:L) with no privileges (PR:N) and no user interaction (UI:N), so the attacker must already have a foothold or the ability to run code on the target. It is not remotely reachable and does not require a victim to open a file or click anything.

Exploitation

CISA added it to the KEV catalog on 2021-11-03 with a 2021-11-17 remediation due date, confirming exploitation in the wild. EPSS gives a 30-day probability of about 6.6 percent (93rd percentile), and no ransomware campaign use is recorded.

What to do

  • Apply the Microsoft security update for CVE-2021-33739 on all affected Windows 10 and Windows Server builds; this is the primary fix.
  • Prioritize patching of internet-facing and high-value endpoints, since the flaw is known to be exploited.
  • Restrict who can run code locally and enforce least privilege to reduce the foothold an attacker needs.
  • Monitor for and block known post-exploitation tooling that relies on local privilege escalation.
  • Verify patch coverage against the affected build list (Windows 10 1909, 2004, 20H2, 21H1 and Windows Server 2004, 20H2).

Detection

  • Hunt for unexpected processes gaining SYSTEM or kernel-level tokens shortly after a low-privilege process starts.
  • Monitor for suspicious interaction with dwm.exe or DWM Core Library components from non-standard parent processes.
  • Alert on known local privilege escalation exploit binaries or scripts executing on unpatched hosts.
  • Correlate endpoint telemetry for privilege changes with the presence of unpatched Windows builds.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-33739 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-33739 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-0796Microsoft SMBv3 buffer overflow remote code executionCVE-2020-0796 is a remote code execution flaw in how Microsoft's SMB 3.1.1 protocol handles certain requests, caused by a memory buffer overflow (CWE…KEVEPSS 100%analysed9.8CVE-2021-31166Microsoft Windows HTTP Protocol Stack use-after-free RCEThe HTTP Protocol Stack in Microsoft Windows 10 2004/20H2 and Windows Server 2004/20H2 contains a use-after-free (CWE-416) that allows remote code ex…KEVEPSS 100%analysed8.8CVE-2023-21674Windows ALPC use-after-free privilege escalationCVE-2023-21674 is a use-after-free (CWE-416) in the Windows Advanced Local Procedure Call (ALPC) subsystem that allows elevation of privilege. It aff…KEVEPSS 41%analysed8.8CVE-2022-41128Windows Scripting Languages out-of-bounds write allows remote code executionCVE-2022-41128 is an out-of-bounds write (CWE-787) in Windows Scripting Languages that leads to remote code execution. Microsoft rates it 8.8 HIGH wi…KEVEPSS 25%analysed8.8CVE-2022-26923Microsoft Active Directory Domain Services certificate validation privilege escalationActive Directory Domain Services fails to properly validate certificate attributes, allowing a low-privileged domain user to obtain a certificate tha…KEVEPSS 84%analysed8.8CVE-2021-40444Microsoft MSHTML remote code execution via malicious Office documentCVE-2021-40444 is a remote code execution flaw in the MSHTML browser rendering engine on Microsoft Windows. An attacker can embed a malicious ActiveX…KEVEPSS 97%analysed8.8CVE-2021-34527Windows Print Spooler privileged file operation RCE (PrintNightmare)The Windows Print Spooler service improperly performs privileged file operations, allowing an attacker to execute arbitrary code as SYSTEM. This is t…KEVEPSS 100%analysed8.8CVE-2020-1020Windows Adobe Type Manager Library font parsing out-of-bounds write RCEMicrosoft Windows Adobe Type Manager Library mishandles a specially crafted multi-master font in Adobe Type 1 PostScript format, causing an out-of-bo…KEVEPSS 65%analysed

Source: NIST National Vulnerability Database (record CVE-2021-33739), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.