
CVE-2021-28310 is a Windows privilege escalation vulnerability in the Desktop Window Manager (DWM) that was exploited in the wild. The root cause is an out-of-bounds write in "dwmcore.dll". By abusing the DirectComposition API, an attacker can write controlled data to a controlled kernel offset due to missing bounds checks. Kaspersky found the exploit while analyzing a separate in-the-wild zero-day (CVE-2021-1732), highlighting how one exploit investigation can uncover another. Beyond the vulnerability itself, the research is worth reading for its deep dive into DirectComposition, DWM internals, and the "NtDComposition*" system calls used to communicate with the kernel.
Post summary
CVE‑2021‑28310 is a privilege‑escalation flaw in DWM that has been actively exploited, with the root cause described as an out‑of‑bounds write via DirectComposition.
