Use-after-free in Microsoft Windows and Windows Server - CVE-2021-40449
Published: October 12, 2021 / Updated: April 3, 2023
Vulnerability identifier: #VU57249
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-40449
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error within the Win32k NtGdiResetDC function in Microsoft Windows kernel. A local user can run a specially crafted program to trigger a use-after-free error, when the function ResetDC is executed a second time for the same handle during execution of its own callback, and execute arbitrary code with elevated privileges.
Note, the vulnerability is being actively exploited in the wild.
The vulnerability exists due to a boundary error within the Win32k NtGdiResetDC function in Microsoft Windows kernel. A local user can run a specially crafted program to trigger a use-after-free error, when the function ResetDC is executed a second time for the same handle during execution of its own callback, and execute arbitrary code with elevated privileges.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Microsoft Windows
Windows Server
Solutions Enabler Virtual Appliance
Solutions Enabler
Unisphere 360
Unisphere for PowerMax Virtual Appliance
Unisphere for PowerMax
VASA Provider Standalone
Windows Server
Solutions Enabler Virtual Appliance
Solutions Enabler
Unisphere 360
Unisphere for PowerMax Virtual Appliance
Unisphere for PowerMax
VASA Provider Standalone
How to mitigate CVE-2021-40449
Install updates from vendor's website.
Solutions Enabler Virtual Appliance - addressed in versions 9.1.0.18, 9.2.3.0
Solutions Enabler - addressed in versions 9.1.0.18, 9.2.3.0
Unisphere 360 - addressed in versions 9.1.0.29, 9.2.3.3
Unisphere for PowerMax Virtual Appliance - addressed in versions 9.1.0.31, 9.2.3.4
Unisphere for PowerMax - addressed in versions 9.1.0.31, 9.2.3.4
VASA Provider Standalone - addressed in versions 9.1.0.723, 9.2.3.0
Solutions Enabler - addressed in versions 9.1.0.18, 9.2.3.0
Unisphere 360 - addressed in versions 9.1.0.29, 9.2.3.3
Unisphere for PowerMax Virtual Appliance - addressed in versions 9.1.0.31, 9.2.3.4
Unisphere for PowerMax - addressed in versions 9.1.0.31, 9.2.3.4
VASA Provider Standalone - addressed in versions 9.1.0.723, 9.2.3.0
Links to Public Exploits and PoC-codes
- Exploit #8957 - Kernel_Exploit (HEVD && CVE Exploit) (April 3, 2023)
- Exploit #7884 - Kernel_Exploit (HEVD & CVE Exploit) (May 24, 2022)
- Exploit #7482 - voidmap (Using CVE-2021-40449 to manual map kernel mode driver) (March 14, 2022)
- Exploit #7367 - CVE-2021-40449-NtGdiResetDC-UAF () (February 21, 2022)
- Exploit #7027 - cve-2021-40449-poc () (November 16, 2021)
- Exploit #6999 - Win32k NtGdiResetDC Use After Free Local Privilege Elevation (November 9, 2021)
- Exploit #6997 - CVE-2021-40449_poc (Exploit for CVE-2021-40449) (November 8, 2021)
- Exploit #6940 - CVE-2021-40449 (LPE exploit for a UAF in Windows (CVE-2021-40449).) (October 26, 2021)
- Exploit #6918 - CVE-2021-40449-Exploit (windows 10 14393 LPE) (October 22, 2021)
- Exploit #6908 - CallbackHell (Exploit for CVE-2021-40449 - Win32k Elevation of Privilege Vulnerability (LPE)) (October 18, 2021)
- Exploit #6906 - CallbackHell (PoC (DoS) for CVE-2021-40449 - Win32k Elevation of Privilege Vulnerability (LPE)) (October 18, 2021)