nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-28310 CVE-2021-28310
HIGHCISA KEV
Win32k Elevation of Privilege Vulnerability
Record summary
CVE-2021-28310 has a selected CVSS score of 7.8 (high); EIP currently links 1 repository PoC. CISA lists CVE-2021-28310 in KEV.
Description
Win32k Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-27072.
Description source: GitHub Advisory
Exploitation context
Known exploitation
- CISA KEV
- Listed · Nov 3, 2021 · CISA
- VulnCheck KEV
- Listed · Apr 13, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 7, 2024 · Source: CVE List
Affected products and versions
11| Product | Source | Version range | Status |
|---|---|---|---|
| CISA | Version data not supplied | ||
Windows 10 Version 1803Browse Microsoft / Windows 10 Version 1803 | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1809Browse Microsoft / Windows 10 Version 1809 | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1909Browse Microsoft / Windows 10 Version 1909 | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 2004Browse Microsoft / Windows 10 Version 2004 | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 20H2Browse Microsoft / Windows 10 Version 20H2 | CVE List | 10.0.0 to < publication | affected |
Windows Server 2019Browse Microsoft / Windows Server 2019 | CVE List | 10.0.0 to < publication | affected |
Windows Server 2019 (Server Core installation)Browse Microsoft / Windows Server 2019 (Server Core installation) | CVE List | 10.0.0 to < publication | affected |
Windows Server version 2004Browse Microsoft / Windows Server version 2004 | CVE List | 10.0.0 to < publication | affected |
Windows Server version 20H2Browse Microsoft / Windows Server version 20H2 | CVE List | 10.0.0 to < publication | affected |
Windows Server, version 1909 (Server Core installation)Browse Microsoft / Windows Server, version 1909 (Server Core installation) | CVE List | 10.0.0 to < publication | affected |
Proofs of concept
1Repository PoCs
GitHubRafael-Svechinskaya/IOC_for_CVE-2021-28310Repository PoCby Rafael-SvechinskayaStars: 0Not analyzed1 file
References
3portal.msrc.microsoft.com
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-28310 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-28310