Buffer overflow in Microsoft Windows and Windows Server - CVE-2021-1732
Published: February 9, 2021 / Updated: April 24, 2023
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error when the Win32k.sys driver in Windows kernel. A local user can run a specially crafted program to trigger memory corruption and execute arbitrary code on the system with elevated privileges.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Windows Server
How to mitigate CVE-2021-1732
Links to Public Exploits and PoC-codes
- Exploit #9002 - CVE-2021-1732 (CVE-2021-1732 Microsoft Windows 10 本地提权漏 研究及Poc/Exploit开发) (April 24, 2023)
- Exploit #8956 - Kernel_Exploit (HEVD && CVE Exploit) (April 3, 2023)
- Exploit #8895 - CVE-2021-1732 (CVE-2021-1732 Microsoft Windows 10 本地提权漏 研究及Poc/Exploit开发) (March 9, 2023)
- Exploit #8793 - CVE-2021-1732 (CVE-2021-1732 Microsoft Windows 10 本地提权漏 研究及Poc/Exploit开发) (February 2, 2023)
- Exploit #8556 - CVE-2021-1732 (CVE-2021-1732 Microsoft Windows 10 本地提权漏 研究及Poc/Exploit开发) (November 1, 2022)
- Exploit #7883 - Kernel_Exploit (HEVD & CVE Exploit) (May 24, 2022)
- Exploit #7770 - Win32k ConsoleControl Offset Confusion (May 12, 2022)
- Exploit #7284 - cve_2021_1732 () (January 27, 2022)
- Exploit #6790 - CVE-2021-1732 () (September 25, 2021)
- Exploit #6753 - CVE-2021-1732_exp () (September 15, 2021)
- Exploit #5497 - CVE-2021-1732 (CVE-2021-1732 poc & exp; tested on 20H2) (May 27, 2021)
- Exploit #5445 - Windows-Privilege-Escalation-CVE-2021-1732 (Read my blog for more info - ) (May 18, 2021)
- Exploit #5351 - Win32k ConsoleControl Offset Confusion (May 9, 2021)
- Exploit #5207 - CVE-2021-1732-Exploit () (March 12, 2021)
- Exploit #5203 - CVE-2021-1732 (CVE-2021-1732 Microsoft Windows 10 本地提权漏 研究及Poc/Exploit开发) (March 9, 2021)
- Exploit #5195 - CVE-2021-1732-Exploit (CVE-2021-1732 Exploit) (March 7, 2021)