{"cveID":"CVE-2021-40449","vendorProject":"Microsoft","product":"Windows","vulnerabilityName":"Microsoft Windows Win32k Privilege Escalation Vulnerability","dateAdded":"2021-11-17","shortDescription":"Unspecified vulnerability allows for an authenticated user to escalate privileges.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2021-12-01","knownRansomwareCampaignUse":"Known","notes":"https://nvd.nist.gov/vuln/detail/CVE-2021-40449","cwes":["CWE-416"],"year":2021,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2021-40449","technique":"T1566","technique_name_at_mapping":"Phishing","mapping_type":"exploitation_technique","capability_group":"priv_escalation","comments":"This vulnerability is exploited by an attacker who has obtained administrative console access on the target system. The vulnerability lies in the Win32k driver, specifically in the NtGdiResetDC function, due to improper handling of user-mode callbacks. This vulnerability has been exploited by threat actors to gain elevated privileges on Windows servers. Attackers leveraged this flaw to execute arbitrary kernel commands, allowing them to manipulate system processes and deploy additional malware to perform further malicious activities.\n\nThe exploit in question is actively being used in the wild, primarily in espionage campaigns. It involves triggering a use-after-free condition by executing the ResetDC function a second time for the same handle during a callback. Once the vulnerability is exploited, attackers can manipulate memory to perform arbitrary kernel function calls with controlled parameters. This allows them to achieve their objectives, such as reading and writing kernel memory, with the same permissions as the compromised system's user.","references":["https://securelist.com/mysterysnail-attacks-with-windows-zero-day/104509/","https://www.darkreading.com/vulnerabilities-threats/microsoft-october-patch-update-includes-fix-for-0-day-flaw-in-win32-driver","https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-40449"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-40449","technique":"T1016","technique_name_at_mapping":"System Network Configuration Discovery","mapping_type":"secondary_impact","capability_group":"priv_escalation","comments":"This vulnerability is exploited by an attacker who has obtained administrative console access on the target system. The vulnerability lies in the Win32k driver, specifically in the NtGdiResetDC function, due to improper handling of user-mode callbacks. This vulnerability has been exploited by threat actors to gain elevated privileges on Windows servers. Attackers leveraged this flaw to execute arbitrary kernel commands, allowing them to manipulate system processes and deploy additional malware to perform further malicious activities.\n\nThe exploit in question is actively being used in the wild, primarily in espionage campaigns. It involves triggering a use-after-free condition by executing the ResetDC function a second time for the same handle during a callback. Once the vulnerability is exploited, attackers can manipulate memory to perform arbitrary kernel function calls with controlled parameters. This allows them to achieve their objectives, such as reading and writing kernel memory, with the same permissions as the compromised system's user.","references":["https://securelist.com/mysterysnail-attacks-with-windows-zero-day/104509/","https://www.darkreading.com/vulnerabilities-threats/microsoft-october-patch-update-includes-fix-for-0-day-flaw-in-win32-driver","https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-40449"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-40449","technique":"T1027","technique_name_at_mapping":"Obfuscated Files or Information","mapping_type":"secondary_impact","capability_group":"priv_escalation","comments":"This vulnerability is exploited by an attacker who has obtained administrative console access on the target system. The vulnerability lies in the Win32k driver, specifically in the NtGdiResetDC function, due to improper handling of user-mode callbacks. This vulnerability has been exploited by threat actors to gain elevated privileges on Windows servers. Attackers leveraged this flaw to execute arbitrary kernel commands, allowing them to manipulate system processes and deploy additional malware to perform further malicious activities.\n\nThe exploit in question is actively being used in the wild, primarily in espionage campaigns. It involves triggering a use-after-free condition by executing the ResetDC function a second time for the same handle during a callback. Once the vulnerability is exploited, attackers can manipulate memory to perform arbitrary kernel function calls with controlled parameters. This allows them to achieve their objectives, such as reading and writing kernel memory, with the same permissions as the compromised system's user.","references":["https://securelist.com/mysterysnail-attacks-with-windows-zero-day/104509/","https://www.darkreading.com/vulnerabilities-threats/microsoft-october-patch-update-includes-fix-for-0-day-flaw-in-win32-driver","https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-40449"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-40449","technique":"T1059.003","technique_name_at_mapping":"Windows Command Shell","mapping_type":"secondary_impact","capability_group":"priv_escalation","comments":"This vulnerability is exploited by an attacker who has obtained administrative console access on the target system. The vulnerability lies in the Win32k driver, specifically in the NtGdiResetDC function, due to improper handling of user-mode callbacks. This vulnerability has been exploited by threat actors to gain elevated privileges on Windows servers. Attackers leveraged this flaw to execute arbitrary kernel commands, allowing them to manipulate system processes and deploy additional malware to perform further malicious activities.\n\nThe exploit in question is actively being used in the wild, primarily in espionage campaigns. It involves triggering a use-after-free condition by executing the ResetDC function a second time for the same handle during a callback. Once the vulnerability is exploited, attackers can manipulate memory to perform arbitrary kernel function calls with controlled parameters. This allows them to achieve their objectives, such as reading and writing kernel memory, with the same permissions as the compromised system's user.","references":["https://securelist.com/mysterysnail-attacks-with-windows-zero-day/104509/","https://www.darkreading.com/vulnerabilities-threats/microsoft-october-patch-update-includes-fix-for-0-day-flaw-in-win32-driver","https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-40449"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-40449","technique":"T1068","technique_name_at_mapping":"Exploitation for Privilege Escalation","mapping_type":"primary_impact","capability_group":"priv_escalation","comments":"This vulnerability is exploited by an attacker who has obtained administrative console access on the target system. The vulnerability lies in the Win32k driver, specifically in the NtGdiResetDC function, due to improper handling of user-mode callbacks. This vulnerability has been exploited by threat actors to gain elevated privileges on Windows servers. Attackers leveraged this flaw to execute arbitrary kernel commands, allowing them to manipulate system processes and deploy additional malware to perform further malicious activities.\n\nThe exploit in question is actively being used in the wild, primarily in espionage campaigns. It involves triggering a use-after-free condition by executing the ResetDC function a second time for the same handle during a callback. Once the vulnerability is exploited, attackers can manipulate memory to perform arbitrary kernel function calls with controlled parameters. This allows them to achieve their objectives, such as reading and writing kernel memory, with the same permissions as the compromised system's user.","references":["https://securelist.com/mysterysnail-attacks-with-windows-zero-day/104509/","https://www.darkreading.com/vulnerabilities-threats/microsoft-october-patch-update-includes-fix-for-0-day-flaw-in-win32-driver","https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-40449"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-40449","technique":"T1071.001","technique_name_at_mapping":"Web Protocols","mapping_type":"secondary_impact","capability_group":"priv_escalation","comments":"This vulnerability is exploited by an attacker who has obtained administrative console access on the target system. The vulnerability lies in the Win32k driver, specifically in the NtGdiResetDC function, due to improper handling of user-mode callbacks. This vulnerability has been exploited by threat actors to gain elevated privileges on Windows servers. Attackers leveraged this flaw to execute arbitrary kernel commands, allowing them to manipulate system processes and potentially deploy additional malware or perform further malicious activities.\n\nThe exploit in question is actively being used in the wild, primarily in espionage campaigns. It involves triggering a use-after-free condition by executing the ResetDC function a second time for the same handle during a callback. Once the vulnerability is exploited, attackers can manipulate memory to perform arbitrary kernel function calls with controlled parameters. This allows them to achieve their objectives, such as reading and writing kernel memory, with the same permissions as the compromised system's user.","references":["https://securelist.com/mysterysnail-attacks-with-windows-zero-day/104509/","https://www.darkreading.com/vulnerabilities-threats/microsoft-october-patch-update-includes-fix-for-0-day-flaw-in-win32-driver","https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-40449"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-40449","technique":"T1082","technique_name_at_mapping":"System Information Discovery","mapping_type":"secondary_impact","capability_group":"priv_escalation","comments":"This vulnerability is exploited by an attacker who has obtained administrative console access on the target system. The vulnerability lies in the Win32k driver, specifically in the NtGdiResetDC function, due to improper handling of user-mode callbacks. This vulnerability has been exploited by threat actors to gain elevated privileges on Windows servers. Attackers leveraged this flaw to execute arbitrary kernel commands, allowing them to manipulate system processes and deploy additional malware to perform further malicious activities.\n\nThe exploit in question is actively being used in the wild, primarily in espionage campaigns. It involves triggering a use-after-free condition by executing the ResetDC function a second time for the same handle during a callback. Once the vulnerability is exploited, attackers can manipulate memory to perform arbitrary kernel function calls with controlled parameters. This allows them to achieve their objectives, such as reading and writing kernel memory, with the same permissions as the compromised system's user.","references":["https://securelist.com/mysterysnail-attacks-with-windows-zero-day/104509/","https://www.darkreading.com/vulnerabilities-threats/microsoft-october-patch-update-includes-fix-for-0-day-flaw-in-win32-driver","https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-40449"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-40449","technique":"T1573.001","technique_name_at_mapping":"Symmetric Cryptography","mapping_type":"secondary_impact","capability_group":"priv_escalation","comments":"This vulnerability is exploited by an attacker who has obtained administrative console access on the target system. The vulnerability lies in the Win32k driver, specifically in the NtGdiResetDC function, due to improper handling of user-mode callbacks. This vulnerability has been exploited by threat actors to gain elevated privileges on Windows servers. Attackers leveraged this flaw to execute arbitrary kernel commands, allowing them to manipulate system processes and potentially deploy additional malware or perform further malicious activities.\n\nThe exploit in question is actively being used in the wild, primarily in espionage campaigns. It involves triggering a use-after-free condition by executing the ResetDC function a second time for the same handle during a callback. Once the vulnerability is exploited, attackers can manipulate memory to perform arbitrary kernel function calls with controlled parameters. This allows them to achieve their objectives, such as reading and writing kernel memory, with the same permissions as the compromised system's user.","references":["https://securelist.com/mysterysnail-attacks-with-windows-zero-day/104509/","https://www.darkreading.com/vulnerabilities-threats/microsoft-october-patch-update-includes-fix-for-0-day-flaw-in-win32-driver","https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-40449"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1016","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"System Network Configuration Discovery","name_at_mapping":"System Network Configuration Discovery","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":12,"has_detection_strategy":true},{"id":"T1027","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Obfuscated Files or Information","name_at_mapping":"Obfuscated Files or Information","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":94,"has_detection_strategy":true},{"id":"T1059.003","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Windows Command Shell","name_at_mapping":"Windows Command Shell","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":46,"has_detection_strategy":true},{"id":"T1068","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploitation for Privilege Escalation","name_at_mapping":"Exploitation for Privilege Escalation","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":31,"has_detection_strategy":true},{"id":"T1071.001","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Web Protocols","name_at_mapping":"Web Protocols","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":42,"has_detection_strategy":true},{"id":"T1082","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"System Information Discovery","name_at_mapping":"System Information Discovery","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":33,"has_detection_strategy":true},{"id":"T1566","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Phishing","name_at_mapping":"Phishing","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":14,"has_detection_strategy":true},{"id":"T1573.001","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Symmetric Cryptography","name_at_mapping":"Symmetric Cryptography","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":0,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"partial","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-24 19:45 UTC","_attack_version":"19.2"}