Skip to main content

CVE detail

CVE-2021-1732

Windows Win32k Elevation of Privilege Vulnerability

CVSS 7.8 · HighBuzz score 71.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 71.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 16.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
20 evidence mentions in the snapshot
Diversity score
16.0
6 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
20 source links · newest first
  • Raspberry Robin Keeps Riding the Wave of Endless 1-DaysCheck Point Research

    Key Findings Introduction Raspberry Robin is a widely distributed worm first reported by Red Canary in 2021. Its capabilities and evasions in addition to its very active distribution made it one of the most intriguing malware out there. We at Check Point Research published an article a couple of months ago using Raspberry Robin as an example […]

    vendorresearch.checkpoint.comFeb 7, 2024, 1:02 PM
  • Google’s Threat Analysis Group Google states that more than 40% of zero-day flaws discovered in 2022 were variants of previous issues. The popular Threat Analysis Group (TAG) Maddie Stone wrote Google’s fourth annual year-in-review of zero-day flaws exploited in-the-wild [2021, 2020, 2019], it is built off of the mid-year 2022 review. In 2022, the researchers […]

    newssecurityaffairs.comJul 30, 2023, 4:38 PM
  • We analyze two Win32k proof-of-concept exploits, CVE-2021-1732 and CVE-2022-21882. These data-only attacks target the Win32k kernel.

    vendorunit42.paloaltonetworks.comJun 20, 2023, 1:00 PM
  • We analyze Microsoft Windows' GUI, how it functions and some of the history of research into its exploitation.

    vendorunit42.paloaltonetworks.comJun 13, 2023, 1:00 PM
  • For May 2023 Patch Tuesday, Microsoft has delivered fixes for 38 CVE-numbered vulnerabilities, including a patch for a Windows bug (CVE-2023-29336) and a Secure Boot bypass flaw (CVE-2023-24932) exploited by attackers in the wild. The two exploited bugs (CVE-2023-29336, CVE-2023-24932) CVE-2023-29336 is a vulnerability that allows attackers to gain SYSTEM privileges. Flagged by researchers with AV maker Avast, it seems probable that it’s being exploited to deliver malware. Microsoft has offered no details about the … More →

    newswww.helpnetsecurity.comMay 9, 2023, 6:58 PM
  • 24th April – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 24th April, please download our Threat_Intelligence Bulletin TOP ATTACKS AND BREACHES The American Bar Association (ABA), the largest global association of lawyers and legal professionals, has suffered a data breach with hackers gaining access to older credentials of 1,466,000 members. The breach was first […]

    vendorresearch.checkpoint.comApr 24, 2023, 4:06 PM
  • Raspberry Robin: Anti-Evasion How-To & Exploit AnalysisCheck Point Research

    Research by: Shavit Yosef Introduction During the last year, Raspberry Robin has evolved to be one of the most distributed malware currently active. During this time, it is likely to be used by many actors to distribute their own malware such as IcedID, Clop ransomware and more. Over time, malware has continued to evolve and escalate […]

    vendorresearch.checkpoint.comApr 18, 2023, 5:16 PM
  • BlueSky ransomware is an emerging family that has adopted modern techniques to evade security defenses. Read our technical analysis.

    vendorunit42.paloaltonetworks.comAug 10, 2022, 7:00 PM
  • Google Project Zero states that in H1 2022 at least half of zero-day issues exploited in attacks were related to not properly fixed old flaws. Google Project Zero researcher Maddie Stone published a blog post that resumes her speech at the FIRST conference in June 2022, the presentation is titled “0-day In-the-Wild Exploitation in 2022…so […]

    newssecurityaffairs.comJul 3, 2022, 1:31 PM
  • Google Project Zero has observed a total of 18 exploited zero-day vulnerabilities in the first half of 2022, at least half of which exist because previous bugs were not properly addressed.

    newswww.securityweek.comJul 1, 2022, 11:12 AM
  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has expanded its list of vulnerabilities known to be exploited in malicious attacks with a recently addressed Windows zero-day flaw.

    newswww.securityweek.comFeb 7, 2022, 11:06 AM
  • US CISA ordered federal agencies to patch their systems against actively exploited CVE-2022-21882 Windows flaw. The Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to address their systems against an actively exploited Windows vulnerability tracked as CVE-2022-21882. “CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence that threat […]

    newssecurityaffairs.comFeb 5, 2022, 9:34 AM
  • If you’re running Windows 10, it’s time to stop delaying those patches and bring your systems up to date as soon…

    newswww.malwarebytes.comJan 31, 2022, 5:00 PM
  • A researcher disclosed an exploit for a Windows local privilege elevation issue (CVE-2022-21882) that allows anyone to gain admin privileges in Windows 10. The security researchers RyeLv has publicly released an exploit for a Windows local privilege elevation flaw (CVE-2022-21882) that allows anyone to gain admin privileges in Windows 10. The Win32k elevation of privilege […]

    newssecurityaffairs.comJan 30, 2022, 6:27 PM
  • Researchers warn of a new evolution of the PurpleFox botnet, operators included exploits and leverage WebSockets for C2 communication. Researchers from TrendMicro have documented a recent evolution of the PurpleFox botnet, the experts discovered a new .NET backdoor, dubbed FoxSocket, that is highly associated with the PurpleFox operation. Its operators have added new exploits and […]

    newssecurityaffairs.comOct 20, 2021, 8:24 PM
  • On this June 2021 Patch Tuesday: Microsoft has fixed 50 security vulnerabilities, six of which are actively exploited zero-days Adobe has delivered security updates for Acrobat and Reader, After Effects, Photoshop, and other products Intel has patched a flurry of flaws in various solutions, though none are critical SAP has released 17 security notes and updated 2 Microsoft’s updates On this June 2021 Patch Tuesday, Microsoft has splatted 5 critical and 45 important bugs. Three … More →

    newswww.helpnetsecurity.comJun 8, 2021, 8:18 PM
  • 15th February – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 15th February, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Russian Internet and e-Commerce giant Yandex has suffered a breach that led to the exposure of almost 5,000 customer accounts. The breach was enabled by a system admin that sold unauthorized access […]

    vendorresearch.checkpoint.comFeb 15, 2021, 5:18 PM
  • Microsoft February 2021 Patch Tuesday addresses 56 vulnerabilities, including a flaw that is known to be actively exploited in the wild. Microsoft February 2021 Patch Tuesday security updates address 56 CVEs in multiple products, including Windows components, .NET Framework, Azure IoT, Azure Kubernetes Service, Microsoft Edge for Android, Exchange Server, Office and Office Services and […]

    newssecurityaffairs.comFeb 9, 2021, 10:27 PM
  • Microsoft’s scheduled monthly batch of security patches landed with a loud thud Tuesday with fixes for at least 56 security vulnerabilities in a range of operating system and software products.

    newswww.securityweek.comFeb 9, 2021, 8:56 PM
  • On this February 2021 Patch Tuesday: Adobe has fixed a Reader flaw used in limited attacks, as well as delivered security updates for a variety of products, including Acrobat and Reader, Dreamweaver, and Magento Microsoft has plugged 56 security holes, including one actively exploited privilege escalation flaw SAP has released 7 new security notes and updated 6 previously released ones Mozilla has fixed a critical vulnerability affecting Firefox and Firefox ESR on Windows Adobe updates … More →

    newswww.helpnetsecurity.comFeb 9, 2021, 8:09 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence