CVE-2021-34498High· 7.8▾ Abyssal0dayWindows GDI Elevation of Privilege Vulnerability
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 42.9 · likelihood 0.2 · exploitation 25
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 10.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.0%
1.0% → 1.0%
Windows GDI Elevation of Privilege Vulnerability
windows_10windows_10 = 20h2windows_10 = 21h1windows_10 = 1607windows_10 = 1809windows_10 = 1909windows_10 = 2004windows_7windows_8.1windows_rt_8.1windows_server_2008windows_server_2008 = r2windows_server_2012windows_server_2012 = r2windows_server_2016windows_server_2016 = 20h2windows_server_2016 = 2004windows_server_2019Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-88097High· 8.1Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.
CVE-2026-85893High· 8.8Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-70341High· 8.5Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
CVE-2026-85360High· 7.0Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-83997High· 8.1Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
CVE-2026-83979High· 7.8Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.