EXPOSURES › CVE-2021-33771
CVE-2021-33771
HIGH ⌖ ON CISA KEV · EXPLOITEDAn unpatched Windows kernel privilege escalation vulnerability was actively exploited in the wild, allowing attackers to escalate privileges without remote code execution.
This unpatched kernel vulnerability (CVE-2021-33771) was listed in CISA's KEV catalog, indicating active exploitation. For DIB organizations, this means systems running unpatched Windows are at risk of privilege escalation, which can lead to data exfiltration or lateral movement. Compliance teams must ensure timely patching and monitor for exploitation attempts.
Shame score — The vulnerability was unpatched long enough to be actively exploited in the wild and included in CISA's KEV catalog, demonstrating a failure to patch known, high-severity flaws.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
"Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation."
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |