Record summary

CVE-2021-28310 has a selected CVSS score of 7.8 (high); EIP currently links 1 repository PoC. CISA lists CVE-2021-28310 in KEV.

Description

Win32k Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-27072.

Description source: GitHub Advisory

Exploitation context

Known exploitation

CISA KEV
Listed · Nov 3, 2021 · CISA
VulnCheck KEV
Listed · Apr 13, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 7, 2024 · Source: CVE List

Affected products and versions

11
ProductSourceVersion rangeStatus
CISAVersion data not supplied
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected

Windows Server 2019 (Server Core installation)

Browse Microsoft / Windows Server 2019 (Server Core installation)
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected

Windows Server, version 1909 (Server Core installation)

Browse Microsoft / Windows Server, version 1909 (Server Core installation)
CVE List10.0.0 to < publicationaffected

Proofs of concept

1

Repository PoCs

GitHubRafael-Svechinskaya/IOC_for_CVE-2021-28310Repository PoCby Rafael-SvechinskayaStars: 0Not analyzed1 file

4.3 KiB

GitHub

PoC details

References

3