PT-2021-2075 · Microsoft · Windows

Jinquan

+4

·

Published

2021-02-09

·

Updated

2026-06-12

·

CVE-2021-1732

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows (affected versions not specified) Windows 10 versions prior to February 2021
Description A memory buffer overflow and type confusion issue exists in the Win32k component of the Windows kernel. During the execution of the NtUserCreateWindowEx() function, an attacker can abuse a user-mode callback to confuse the win32k.sys driver regarding the cbWndExtra and pExtraBytes fields. This allows the SetWindowLongPtr() function to be used as an arbitrary kernel read/write primitive, enabling an attacker to overwrite the current process token with the SYSTEM token to gain full privileges. This issue has been actively exploited in the wild by the APT Bitter group and integrated into the Disco malware framework to facilitate privilege escalation. It was also observed in attacks targeting medical institutions to deploy cryptocurrency miners.
Recommendations Update Windows 10 to the February 2021 security update or a newer version. At the moment, there is no information about a newer version that contains a fix for this vulnerability for other unspecified Windows versions.

Exploit

Fix

DoS

LPE

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2021-00926
CVE-2021-1732

Affected Products

Windows