HIGH

CVE-2021-28310

Microsoft Windows 10 1803 2021-04-13 CVSS v3.1
CVSS
7.8
KEV

Description

Win32k Elevation of Privilege Vulnerability

Summary dbcve.org

A vulnerability in the Windows Win32k kernel subsystem that allows an authenticated attacker to elevate privileges to SYSTEM level. The specific technical exploitation mechanism (e.g., buffer overflow, use-after-free) is not detailed in the available description.

Mitigation

Apply the relevant Microsoft security update for CVE-2021-28310, which was released as part of the March 2021 Windows security updates.

Patch Commit

Weakness (CWE)

CWE-787 Out-of-bounds Write

EPSS Score

8.33%
Probability of exploitation in next 30 days
94.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE