LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-41357: Microsoft Win32k Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 16, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-41357 to its Known Exploited Vulnerabilities catalog on Apr 25, 2022, with a federal patch deadline of May 16, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

CVE-2021-41357 is a privilege escalation vulnerability in Microsoft Win32k, the Windows kernel-mode graphics and window-management component. An attacker who already has some level of access on a system could use it to gain higher privileges. For IT and security teams this matters because successful elevation often turns a limited foothold into full system control, enabling persistence, lateral movement, or further compromise. Public detail on the exact flaw is limited; confirm all specifics against the Microsoft advisory.

How it works

Win32k runs in kernel mode and handles core user-interface and graphics operations. The CISA summary describes an unspecified vulnerability that allows privilege escalation. In general terms for this class of issue, a local attacker with the ability to run code or interact with Win32k interfaces can trigger the flaw to obtain elevated rights, typically SYSTEM or equivalent kernel-level privileges.

Exact exploitation mechanics, preconditions, and any required user interaction are not detailed in the provided information. Defenders should treat it as a local elevation-of-privilege weakness in a privileged Windows component and rely on the vendor advisory for technical depth rather than assuming particular trigger methods or reliability.

Am I affected? How to find it in your systems

Microsoft Win32k is present on essentially all supported Windows client and server installations that use the graphical subsystem. It is not an optional add-on; it is part of the core OS.

How to remediate

Patch first. Apply the Microsoft security update that resolves CVE-2021-41357 according to the vendor instructions and your normal change process. CISA’s required action is simply to apply updates per vendor instructions.

If you can't patch immediately

Compensating controls reduce but do not eliminate risk until the update is applied.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities frequently appear in breach chains once an initial foothold exists. Known ransomware use of this specific CVE is not documented in the supplied facts. If you have reason to believe systems were compromised before patching, follow your incident-response process: isolate affected hosts, preserve evidence, reset credentials, and hunt for persistence. As a quick personal check, you can run a free exposure scan of your email addresses against known breach data sets to see whether associated accounts have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Win32k
Added to CISA KEVApr 25, 2022
Federal patch deadlineMay 16, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities