PT-2021-2694 · Microsoft · Windows

Boris Larin

+1

·

Published

2021-04-13

·

Updated

2026-03-10

·

CVE-2021-28310

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows (affected versions not specified)
Description The issue is related to a privilege escalation vulnerability in the Windows operating system, specifically in the Desktop Window Manager. It is caused by a buffer overflow in memory, which can be exploited by an attacker using a specially crafted application to elevate their privileges. The vulnerability has been used in the wild, with reports of exploitation. There is no information on the estimated number of potentially affected devices worldwide.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02225
CVE-2021-28310

Affected Products

Windows