{"id":"CVE-2021-1732","title":"Windows Win32k Elevation of Privilege Vulnerability","summary":"Windows Win32k Elevation of Privilege Vulnerability","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-787","CWE-787"],"vendor":"microsoft","product":"windows_10_1803","affected":["windows_10_1803","windows_10_1809","windows_10_1909","windows_10_2004","windows_10_20h2","windows_server_1909","windows_server_2004","windows_server_2019","windows_server_20h2"],"published":"2021-02-25","updated":"2026-08-12","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-1732","references":[{"url":"http://packetstormsecurity.com/files/161880/Win32k-ConsoleControl-Offset-Confusion.html","label":"secure@microsoft.com"},{"url":"http://packetstormsecurity.com/files/166169/Win32k-ConsoleControl-Offset-Confusion-Privilege-Escalation.html","label":"secure@microsoft.com"},{"url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-1732","label":"secure@microsoft.com"},{"url":"http://packetstormsecurity.com/files/161880/Win32k-ConsoleControl-Offset-Confusion.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://packetstormsecurity.com/files/166169/Win32k-ConsoleControl-Offset-Confusion-Privilege-Escalation.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-1732","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-1732","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.78376,"epssPercentile":0.99575,"kev":true,"kevDateAdded":"2021-11-03","kevDueDate":"2021-11-17","kevRansomware":true,"exploited":true,"zeroDay":true,"ingestedAt":"2026-08-12T19:54:25.608Z","exploits":{"github":13,"githubRepos":["https://github.com/KaLendsi/CVE-2021-1732-Exploit","https://github.com/flyinbedxyz/CVE-2021-1732","https://github.com/oneoy/CVE-2021-1732-Exploit"],"metasploit":["exploit/windows/local/cve_2022_21882_win32k"],"checkedAt":"2026-09-21T15:24:08.705Z"},"exploitAvailable":true,"slug":"CVE-2021-1732","body":"## Overview\n\nWindows Win32k Elevation of Privilege Vulnerability\n\n## Affected\n\n- `windows_10_1803`\n- `windows_10_1809`\n- `windows_10_1909`\n- `windows_10_2004`\n- `windows_10_20h2`\n- `windows_server_1909`\n- `windows_server_2004`\n- `windows_server_2019`\n- `windows_server_20h2`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":89,"depthScoreParts":{"impact":42.9,"likelihood":15.7,"exploitation":25,"ransomware":5},"changes":[{"seq":4499,"id":"CVE-2021-1732","ts":1788887185889,"field":"exploit_available","old":"false","new":"true"},{"seq":3382,"id":"CVE-2021-1732","ts":1788886303616,"field":"exploit_available","old":"true","new":"false"},{"seq":2237,"id":"CVE-2021-1732","ts":1788882973256,"field":"exploit_available","old":"false","new":"true"},{"seq":1266,"id":"CVE-2021-1732","ts":1788882384909,"field":"exploit_available","old":"true","new":"false"},{"seq":380,"id":"CVE-2021-1732","ts":1788881820226,"field":"exploit_available","old":"false","new":"true"}]}