Vulnerability record · CVE-2021-33771 · published 14 July 2021
CVE-2021-33771: Windows Kernel Elevation of Privilege Flaw
Microsoft · Windows 10 1507
CVE-2021-33771 is an elevation of privilege vulnerability in the Windows kernel. A local attacker with low privileges can exploit it to gain full control of confidentiality, integrity and availability on the host. It affects a broad set of Windows 10, Windows 8.1, Windows RT 8.1 and Windows Server releases.
Description
Windows Kernel Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is confirmed exploited in the wild and listed in CISA KEV, but requires local low-privileged access, limiting it to a post-compromise escalation role.
What it is
CVE-2021-33771 is an elevation of privilege vulnerability in the Windows kernel. A local attacker with low privileges can exploit it to gain full control of confidentiality, integrity and availability on the host. It affects a broad set of Windows 10, Windows 8.1, Windows RT 8.1 and Windows Server releases.
Impact
An attacker who exploits the flaw gains SYSTEM-level privileges from a low-privileged local context, enabling full compromise of the affected machine.
Attack surface
The CVSS vector AV:L/PR:L/UI:N indicates the flaw is reached locally by an authenticated low-privileged user with no user interaction. It is not remotely reachable over the network.
Exploitation
CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2021-11-03, confirming in-the-wild exploitation; EPSS gives a 30-day probability of roughly 10.2 percent (95th percentile). No ransomware campaign use is recorded.
What to do
- Apply the Microsoft security update for CVE-2021-33771 on all affected Windows 10, Windows 8.1, Windows RT 8.1 and Windows Server versions.
- Prioritize patching of systems where untrusted users have local logon or code execution, such as multi-user and remote-access hosts.
- Restrict local interactive and remote desktop access to only necessary accounts to reduce the pool of low-privileged users who can trigger the flaw.
- Monitor for and block unapproved kernel driver or exploit tooling execution on endpoints.
Detection
- Alert on processes that gain SYSTEM token or spawn from unexpected low-privileged parents, especially near kernel exploitation activity.
- Monitor for known public exploit artifacts and suspicious driver loads associated with Windows kernel privilege escalation.
- Correlate local privilege escalation events with subsequent credential access or lateral movement in EDR telemetry.
- Track patch state of the affected Windows builds against the vendor advisory to find unpatched hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-33771 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Windows Kernel Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
14 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-33771 | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-33771 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-33771 | US Government Resource |
Track CVE-2021-33771 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-33771), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.