Researchers reported that the BITTER APT group used a Windows zero-day, CVE-2021-28310, to gain elevated privileges in targeted attacks. The flaw affects Desktop Window Manager via dwmcore.dll and stems from an out-of-bounds write reachable through the DirectComposition API. Kaspersky said it uncovered the issue while investigating exploitation activity linked to CVE-2021-1732, indicating the vulnerability was likely used as part of a broader exploit chain rather than as a standalone compromise method.
Microsoft confirmed the bug as a zero-day after receiving the report in February 2021 and later fixed it in its April 2021 security updates. According to the technical analysis, attackers could abuse inconsistencies between kernel-mode and user-mode property handling in DirectComposition to bypass checks, potentially escaping browser sandboxes or obtaining SYSTEM-level privileges. Researchers said the exploit had been used in the wild, but they did not capture the full chain or determine whether it was paired with another browser zero-day or previously patched vulnerabilities.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft released a fix for CVE-2021-28310 as part of its April 2021 security updates. The vulnerability affected dwmcore.dll and could be exploited for elevation of privilege.
While analyzing exploitation tied to CVE-2021-1732, Kaspersky discovered a separate zero-day elevation-of-privilege flaw in Desktop Window Manager and reported it to Microsoft. Microsoft confirmed it as a zero-day and assigned it CVE-2021-28310.
Kaspersky publicly reported that CVE-2021-28310 had been used in the wild and linked the activity to the same actor associated with CVE-2021-1732 exploitation, the BITTER APT group. The company said the flaw was likely used as part of a larger exploit chain, such as escaping a browser sandbox or gaining system privileges.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.