LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-33771: Microsoft Windows Kernel Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-33771 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.

CVE-2021-33771 is a privilege-escalation vulnerability in the Microsoft Windows kernel. An attacker who already has a foothold on a system could use it to gain higher privileges. Because the kernel sits at the core of the operating system, successful abuse can undermine isolation between processes and users, which is why Windows administrators treat kernel elevation flaws as high priority.

Public detail on the exact root cause is limited; CISA describes an unspecified kernel vulnerability that allows privilege escalation. Confirm affected builds, patch identifiers, and any exploitation notes directly against the Microsoft security advisory before acting.

How it works

The weakness is classified as CWE-119 (improper restriction of operations within the bounds of a memory buffer). In kernel code this class of flaw typically arises when a buffer, structure, or pointer is handled without adequate bounds or validation checks. An attacker who can already execute code at a lower privilege level may supply crafted input that causes the kernel to read or write outside the intended memory region.

If the resulting corruption can be controlled, the attacker may overwrite security-critical data such as tokens, function pointers, or object attributes. That can let the malicious process assume SYSTEM or equivalent rights. Exact trigger conditions, IOCTL paths, or memory layouts are not provided in the public summary; treat any technical write-ups as unconfirmed until verified against the vendor advisory. No specific exploit code or ransomware linkage is documented for this CVE.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows. Kernel components ship with every supported Windows client and server installation, so the attack surface is broad: workstations, servers, virtual machines, and any appliance built on Windows.

How to remediate

Apply the security update Microsoft released for CVE-2021-33771. Follow the vendor’s installation and reboot guidance exactly; kernel patches normally require a restart.

If you can't patch immediately

Compensating controls reduce but do not eliminate risk.

Schedule the official patch as soon as operational constraints allow; compensating controls are not a substitute for the vendor fix.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities are commonly used after an initial compromise to move laterally or access sensitive data. If you have evidence of exploitation or suspect a breach, follow your incident-response plan: isolate affected hosts, preserve volatile evidence, and rotate credentials that may have been accessible to the elevated process. You can also run a free exposure scan of your email addresses against known breach data sets to see whether associated accounts appear in prior leaks, then force password resets and enable multi-factor authentication where needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-119
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities