LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-33739: Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-33739 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation.

CVE-2021-33739 is a privilege-escalation vulnerability in the Microsoft Desktop Window Manager (DWM) Core Library on Microsoft Windows. An attacker who already has a foothold on a system could use it to gain higher privileges, which matters because elevated access often enables further persistence, lateral movement, or data access. Public detail on the exact weakness is limited; confirm all specifics against the vendor advisory.

CISA notes that the DWM Core Library contains an unspecified vulnerability allowing privilege escalation and directs organizations to apply updates per vendor instructions. Known ransomware use is not documented for this CVE.

How it works

This is a privilege-escalation issue in the Desktop Window Manager Core Library, a component of the Windows graphical subsystem that manages window composition and related desktop rendering tasks. Because the CWE is not specified in the available facts, the precise flaw class (for example, memory corruption, improper access control, or another issue) must be confirmed against the Microsoft advisory.

In general terms for this class of vulnerability, an attacker who can already run code in a less-privileged context on the affected system abuses the flaw in the DWM component to obtain higher privileges—typically moving toward SYSTEM or an equivalent administrative level. The CISA summary describes the impact as privilege escalation but does not provide exploit mechanics; do not assume particular primitives or attack chains beyond what the vendor documents. Successful abuse would let the attacker perform actions reserved for higher-privileged accounts on that host.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems that include the Desktop Window Manager Core Library. DWM is a standard part of modern Windows desktop and server SKUs that support the graphical shell, so it is commonly present on endpoints, VDI hosts, and any Windows systems where the desktop composition stack runs.

How to remediate

Patch first. Apply the Microsoft updates that address CVE-2021-33739 exactly as directed in the vendor advisory and per CISA’s required action to apply updates per vendor instructions. Use your standard enterprise deployment path (WSUS, SCCM, Intune, Microsoft Update, or approved offline media) and verify installation across the estate.

If you can't patch immediately

Until the vendor update can be deployed, reduce risk with compensating controls appropriate to a local privilege-escalation vulnerability in a core Windows component.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities can contribute to broader compromise and data exposure once an attacker has elevated rights. If you suspect exploitation, follow your incident-response process: isolate affected hosts, preserve forensic data, rotate credentials that may have been accessible, and assess what data or systems the elevated account could reach. Known ransomware use is not documented for this CVE in the provided facts; still treat confirmed elevation seriously. You can run a free exposure scan of your email addresses against known breach data to check whether credentials or identities tied to your environment have appeared in prior breaches, then combine that with internal investigation findings.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities