ZeroHour

CVE-2021-31955

KEVmass

Windows Kernel Information Disclosure Vulnerability Actively Exploited (CVE-2021-31955)

CISA: Microsoft Windows Kernel Information Disclosure Vulnerability

CVSS 3.1
5.5 medium
EPSS
81%p100
Published
()
KEV added
AI analysis

CVE-2021-31955 is an information disclosure flaw in the Windows kernel (CWE-497) that leaks sensitive kernel information to a locally running attacker. It is triggered by executing a malicious, specially crafted application on an affected Windows system; the attack vector is local, requires only low privileges, and needs no user interaction. Successful exploitation gives the attacker access to sensitive system information (high confidentiality impact), which is typically valuable for reconnaissance or as part of a chained attack with other kernel bugs. Organizations running Windows 10 versions 1809 through 21H1 and Windows Server 2019/2004/20H2 prior to the June 2021 security updates are affected. The flaw was exploited in the wild — Microsoft fixed it among six actively exploited zero-days in June 2021 Patch Tuesday, CISA added it to the KEV catalog on 2021-11-03, and EPSS assigns it an 81.1% probability of exploitation within 30 days.

What to do: Apply the June 2021 Windows cumulative security updates per vendor instructions to Windows 10 (1809, 1909, 2004, 20H2, 21H1) and Windows Server 2019/2004/20H2, then verify affected devices are running updated builds. Because this flaw was exploited in the wild and is on CISA's KEV list, patch it on a priority timeline and check for signs of local malicious code execution. Where patching is delayed, limit local code execution on affected hosts and prioritize internet-exposed servers.

Affected
microsoft Windows 101809, 1909, 2004, 20H2, 21H1 (builds prior to the June 2021 security updates)
microsoft Windows Server 2019affected builds prior to the June 2021 security updates
microsoft Windows Server 2004affected builds prior to the June 2021 security updates
microsoft Windows Server 20H2affected builds prior to the June 2021 security updates
Estimated exposure
masshundreds of millions of Windows 10/Server installations worldwide — These versions were mainstream supported Windows 10 and Windows Server releases in mid-2021, and the Windows 10 installed base alone is on the order of hundreds of millions of devices, so the number of potentially affected installations…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Kernel Information Disclosure Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1809, windows 10 1909, windows 10 2004, windows 10 20h2, windows 10 21h1, windows server 2004, windows server 2019, windows server 20h2
Weakness
CWE-497
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news