PT-2021-4388 · Microsoft · Win32K+1

·

CVE-2021-40449

·

Published

2021-10-12

·

Updated

2026-07-07

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows 10 1507 versions prior to 10.0.10240.19086 Microsoft Windows 10 1607 versions prior to 10.0.14393.4704 Microsoft Windows 10 1809 versions prior to 10.0.17763.2237 Microsoft Windows 10 1909 versions prior to 10.0.18363.1854 Microsoft Windows 10 2004 versions prior to 10.0.19041.1288
Description An elevation-of-privilege issue exists in the Win32k component (win32kfull.sys) of the Windows operating system. The flaw is caused by a use-after-free condition, which occurs when the kernel invokes user-mode callbacks and incorrectly assumes that an object remains unchanged after the callback returns. An attacker can exploit this by modifying, freeing, or replacing the object to gain elevated privileges on the system.
Recommendations Update Microsoft Windows 10 1507 to version 10.0.10240.19086 or later. Update Microsoft Windows 10 1607 to version 10.0.14393.4704 or later. Update Microsoft Windows 10 1809 to version 10.0.17763.2237 or later. Update Microsoft Windows 10 1909 to version 10.0.18363.1854 or later. Update Microsoft Windows 10 2004 to version 10.0.19041.1288 or later.

Exploit

Fix

LPE

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05018
CVE-2021-40449

Affected Products

Win32K
Windows