CVE-2021-28310Active Exploitation(microsoft / windows_10_1803)

CRITICALCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch microsoft windows_10_1803 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Win32k Elevation of Privilege Vulnerability

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2021-11-17. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-787

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1803
  • windows_10_1809
  • windows_10_1909
  • windows_10_2004

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
windows_10_1803windows_10_1809windows_10_1909windows_10_2004windows_10_20h2windows_server_1909windows_server_2004windows_server_2019windows_server_20h2

1 version affected across 9 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-02: 2PoC Mentioned / Linked · 2026-07-02: 1Exploit Tool / Code · 2026-07-02: 1Active Exploitation · 2026-07-02: 2Patch / Workaround · 2026-07-02: 1Technical Details · 2026-07-02: 207-02
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets1 URL
Full discourse2 posts
  • OS Dev@OSdev_
    Active Exploitation

    CVE-2021-28310 is a Windows privilege escalation vulnerability in the Desktop Window Manager (DWM) that was exploited in the wild. The root cause is an out-of-bounds write in "dwmcore.dll". By abusing the DirectComposition API, an attacker can write controlled data to a controlled kernel offset due to missing bounds checks. Kaspersky found the exploit while analyzing a separate in-the-wild zero-day (CVE-2021-1732), highlighting how one exploit investigation can uncover another. Beyond the vulnerability itself, the research is worth reading for its deep dive into DirectComposition, DWM internals, and the "NtDComposition*" system calls used to communicate with the kernel.

    Post summary

    CVE‑2021‑28310 is a privilege‑escalation flaw in DWM that has been actively exploited, with the root cause described as an out‑of‑bounds write via DirectComposition.

    15066223.3K
    5.0K followersView on X
  • OS Dev@OSdev_
    Active Exploitation

    https://securelist.com/zero-day-vulnerability-in-desktop-window-manager-cve-2021-28310-used-in-the-wild/101898/

    Post summary

    The SecureList article reports that CVE‑2021‑28310, a critical Windows Desktop Window Manager vulnerability, was actively exploited in the wild; it includes a PoC, details of the exploitation method, and notes that Microsoft has released a patch.

    01020352
    5.0K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1803---
OSmicrosoftwindows_10_1809---
OSmicrosoftwindows_10_1909---
OSmicrosoftwindows_10_2004---
OSmicrosoftwindows_10_20h2---
OSmicrosoftwindows_server_1909---
OSmicrosoftwindows_server_2004---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_20h2---

Explore more