Vulnerability record · CVE-2021-40449 · published 13 October 2021
CVE-2021-40449: Windows Win32k use-after-free local privilege escalation
Microsoft · Windows 10 1507
CVE-2021-40449 is a use-after-free (CWE-416) in the Windows Win32k component that allows a local attacker to elevate privileges. It affects a broad set of Windows client and server releases, and Microsoft has published a patch. Because it is a kernel-level elevation flaw with public exploit code and confirmed in-the-wild use, it is a serious risk on unpatched systems.
Description
Win32k Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a patched but actively exploited local privilege escalation flaw in CISA KEV with known ransomware use and very high EPSS, though it requires local access.
What it is
CVE-2021-40449 is a use-after-free (CWE-416) in the Windows Win32k component that allows a local attacker to elevate privileges. It affects a broad set of Windows client and server releases, and Microsoft has published a patch. Because it is a kernel-level elevation flaw with public exploit code and confirmed in-the-wild use, it is a serious risk on unpatched systems.
Impact
A local attacker who can run code on the host can exploit the flaw to gain higher privileges, typically SYSTEM, on the affected Windows machine. That access can then be used to disable defenses, persist, or move laterally.
Attack surface
The attack is local (CVSS vector AV:L) and requires low privileges (PR:L) with no user interaction (UI:N). It is reached by running crafted code on the target system, not over the network.
Exploitation
CVE-2021-40449 is listed in CISA KEV with a due date of 2021-12-01 and is flagged for known ransomware campaign use; EPSS 30-day probability is about 0.74 (99.5th percentile). Public exploit code is referenced by Packet Storm, so exploitation is both practical and observed.
What to do
- Apply the Microsoft security update for CVE-2021-40449 on all affected Windows client and server versions.
- Prioritize patching internet-facing and high-value systems, and any host where untrusted local code can run.
- Restrict local logon and code execution rights to reduce the pool of users who can trigger the flaw.
- Enable and tune EDR/AV to block known Win32k exploitation behavior and monitor for privilege escalation attempts.
- Verify patch coverage across the full affected product list, including older Windows 7, 8.1, and Server 2008/2012 builds.
Detection
- Monitor for unexpected processes gaining SYSTEM or high-integrity tokens shortly after user-level execution.
- Hunt for known Win32k/NtGdiResetDC use-after-free exploitation patterns and crash artifacts in Win32k.
- Correlate local privilege escalation events with subsequent defense evasion, persistence, or ransomware precursor activity.
- Audit hosts for missing patches matching the affected Windows versions and flag unpatched endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-40449 to the Known Exploited Vulnerabilities catalog on 17 November 2021 as "Microsoft Windows Win32k Privilege Escalation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 1 December 2021.
Affected products
19 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/164926/Win32k-NtGdiResetDC-Use-After-Free-Local-Privilege-Escalation.html | ExploitThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40449 | PatchVendor Advisory |
| http://packetstormsecurity.com/files/164926/Win32k-NtGdiResetDC-Use-After-Free-Local-Privilege-Escalation.html | ExploitThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40449 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-40449 | US Government Resource |
Track CVE-2021-40449 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-40449), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.