CVE-2021-1732 is a local elevation-of-privilege vulnerability in Windows Win32k. A window object type confusion leads to an out-of-bounds write, enabling exploitation through arbitrary read and write primitives. Observed exploits use GetMenuBarInfo and SetWindowLong and locate process structures to replace the current process token with a SYSTEM token. Exploitation has targeted Windows 10 and Windows Server 2019; one documented implementation targets Windows 10 builds 16353 through 19042. The vulnerability was exploited as a zero-day by BITTER and subsequently incorporated into multiple malware campaigns.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
8 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
The repository contains a standalone C++ exploit for CVE-2021-1732, not a detection script or an exploit-framework module. Its eight files comprise a Visual Studio solution, project and filter metadata, the main exploit source, two utility files, a HookLib header, and a .gitignore. Four files contain C++ source or declarations. The visible exploit defines a 512-window spray, locates HMValidateHandle through user32!IsMenu, and calculates window-object offsets relative to the desktop heap. Its user-mode callback proxy invokes NtUserConsoleControl with control code 0x6 and supplies a desktop-heap-relative value through NtCallbackReturn during window extra-byte allocation. Later visible code uses manipulated neighboring window objects and fake-menu-based reads to access kernel memory, redirects window extra-byte writes into a token object, modifies token fields, and invokes CreateEopProc(). It subsequently restores several altered window fields. Util.cpp resolves NtQuerySystemInformation and enumerates extended system handles to obtain kernel object addresses. HookLib.h supplies generic interception declarations and wrappers, not a separate exploitation framework. The exploit is architecture- and build-sensitive: it uses x64 intrinsics and hardcoded TEB, thread, desktop, window, and token offsets. Although the solution lists x86 and x64 configurations, the visible implementation targets x64, and only Debug x64 explicitly configures HookLib search paths. Required HookLib and Zydis library binaries are missing from the inventory. The main source is truncated, preventing confirmation of the complete trigger sequence and elevated-process payload. No network communication, remote target, registry access, persistence, or exfiltration is visible. Repository URL, Git reference, and archive size were not supplied; empty metadata and a zero size represent unknown values.
The repository contains a short README and one 56 KB self-contained HTML/JavaScript exploit. `exploit.html` implements a staged browser-to-SYSTEM chain: it parses stage/run/retry parameters, performs low-level JavaScript memory manipulation consistent with an IonMonkey native-code-execution attempt for CVE-2019-11707, and uses a privileged `Prompt:Open` message path intended to reach the Firefox parent process (CVE-2019-11708). It then includes a large Base64-embedded Donut x64 payload described as a CVE-2021-1732 Windows privilege-escalation executable. The stated final action is an elevated `cmd.exe /k whoami` command prompt. It has retry and pointer-drift checks, restores modified class pointers on exceptions, and contains optional localhost-only hold/signaling instrumentation; it does not require external exploit hosting, fixed module bases, or profile modifications according to its comments. The README only links to external research and a demonstration video.
This repository contains a single Metasploit module implementing a local privilege escalation exploit for the Win32k ConsoleControl Offset Confusion vulnerability (CVE-2022-21882), which is a patch bypass of CVE-2021-1732. The exploit targets Windows 10 (versions 1803-21H2 x64), Windows 11 21H2, Server 2019, and Server 2022. The module is written in Ruby and leverages Metasploit's post-exploitation and reflective DLL injection capabilities. The exploit works by manipulating the WndExtra field of a window object in the Windows kernel, leading to an out-of-bounds write and privilege escalation to SYSTEM. The payload is customizable and injected as a DLL, typically resulting in a privileged Meterpreter shell. The module includes checks for target compatibility and architecture, and will fail gracefully if the session is already elevated or if the architecture is unsupported. The only fingerprintable endpoint is the DLL file used for injection. The repository is weaponized, as it is part of the Metasploit framework and allows for easy payload customization and deployment.
This repository contains a working local privilege escalation exploit for CVE-2021-1732, a vulnerability in the Windows Win32k component affecting Windows 10 versions 1809 and 1909 x64. The main exploit logic is implemented in 'CVE-2021-1732_Exploit.cpp', which is a C++ source file. The exploit abuses window and menu object manipulation to achieve arbitrary kernel memory read/write, ultimately replacing the process token to gain SYSTEM privileges. The repository includes Visual Studio project files for building the exploit, as well as documentation in both English and Chinese. The exploit must be run locally on a vulnerable system and, if successful, provides a SYSTEM shell. No network or remote attack vector is present; the exploit is strictly local. The code is operational and demonstrates a full privilege escalation chain, but does not include a customizable payload framework.
This repository contains a working proof-of-concept (PoC) exploit for CVE-2021-1732, a local privilege escalation vulnerability in Microsoft Windows 10 (x64), specifically in the win32k.sys kernel component. The main exploit logic resides in 'CVE-2021-1732/CVE-2021-1732.cpp', which orchestrates the attack by creating and manipulating a large number of window objects, exploiting the desktop heap, and leveraging internal Windows APIs and structures. The exploit uses custom hooking (via HookLib) and direct system calls to manipulate kernel memory, ultimately allowing the attacker to overwrite process tokens and spawn a process with SYSTEM privileges. Supporting files include utility code for querying system handles and project files for building the exploit with Visual Studio. No network endpoints are present; the attack vector is strictly local, requiring code execution on the target machine. The code is a functional PoC and demonstrates a deep understanding of Windows internals and kernel exploitation techniques.
This repository contains a working local privilege escalation exploit for CVE-2021-1732, a Windows kernel vulnerability affecting multiple versions of Windows 10 and Windows Server. The main file, 'CVE-2021-1732_Exploit.cpp', is a C++ implementation that leverages window and menu object manipulation to achieve arbitrary kernel memory read/write, ultimately elevating the attacker's privileges to SYSTEM. The exploit is operational and requires local access to a vulnerable system. The README provides a comprehensive list of affected Windows versions and a demonstration image. No network endpoints are present; the attack vector is purely local. The code interacts with Windows system DLLs (notably user32.dll) and kernel structures, and is intended for advanced users familiar with Windows internals and exploit development.
This repository contains a working local privilege escalation exploit for CVE-2021-1732, a vulnerability in the Windows kernel (win32k.sys) affecting multiple versions of Windows 10 and Windows Server. The main file, 'CVE-2021-1732_Exploit.cpp', is a C++ implementation that leverages window and menu object manipulation to achieve arbitrary kernel memory read/write, ultimately allowing the attacker to escalate privileges to SYSTEM. The exploit is operational and requires local access to a vulnerable system. The README provides a list of affected Windows versions and a demonstration image. No network endpoints are present; the attack vector is purely local. The code interacts with system DLLs such as user32.dll and targets the win32k.sys kernel driver. The repository is structured simply, with one exploit source file and a README.
This repository contains a working local privilege escalation exploit for CVE-2021-1732, a vulnerability in the Windows kernel (Win32k component) affecting Windows 10 (versions 1803-20H2) and Windows Server 2019/2004. The main exploit logic is implemented in 'CVE-2021-1732/CVE-2021-1732.cpp', which orchestrates the attack by creating and manipulating window objects, spraying window handles, and abusing internal kernel structures via user-mode callbacks and desktop heap offsets. The exploit leverages custom hooks (via HookLib) and direct system calls to manipulate kernel memory and escalate privileges to SYSTEM. Supporting files include utility code for handle enumeration and project files for building the exploit. The README provides affected versions and a demonstration GIF. No network endpoints are present; the attack vector is strictly local, requiring code execution on a vulnerable Windows system. The exploit is operational and provides a SYSTEM shell or process upon success.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A privilege-escalation vulnerability associated with exploit malware deployed during the second attack against a Korean medical institution's Windows IIS server. The attack ultimately installed XMRig cryptocurrency-mining malware; the report does not confirm execution or success of the CVE-specific exploit.
Windows Win32k elevation of privilege zero-day referenced as the original issue later bypassed by CVE-2022-21882.
A specific privilege escalation vulnerability that MoustachedBouncer exploited to run malware components with elevated rights.
A Windows local privilege escalation vulnerability exploited by a MoustachedBouncer (Disco) plugin to run code with elevated privileges.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.