ZeroHour

CVE-2021-31956

KEVmass

Local Privilege Escalation via Out-of-Bounds Write in Microsoft Windows NTFS

CISA: Microsoft Windows NTFS Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
22%p98
Published
()
KEV added
AI analysis

Microsoft Windows NTFS contains a privilege escalation flaw in which improper handling of integer underflow/overflow (CWE-191) leads to an out-of-bounds write (CWE-787), exploitable via a specially crafted application. A local attacker who can run such an application on a vulnerable Windows system can trigger the flaw and gain elevated privileges on that host. Because the flaw resides in the file system component shipped with Windows, essentially all supported Microsoft Windows releases are in scope. Exploitation is confirmed in the wild: CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2021-11-03 with a required action to apply vendor updates, though ransomware usage is unknown and no public proof-of-concept is cataloged. Predictive scoring (EPSS) places the 30-day exploitation probability at 22.3% (98th percentile).

What to do: Apply Microsoft security updates on all Windows systems per vendor instructions; this flaw was remediated in Microsoft's June 2021 monthly security (cumulative) updates, so verify each Windows build's installed cumulative update level against the Microsoft advisory. Prioritize patching multi-user and shared systems (terminal/RDS servers, kiosks, shared workstations) where local attackers can run untrusted code. As interim mitigation, restrict execution of untrusted local applications on vulnerable hosts.

Affected
Microsoft WindowsMultiple supported Windows releases (specific affected version ranges not enumerated in the source data; see Microsoft advisory for exact affected builds)
Estimated exposure
mass~1 billion+ Windows systems (NTFS is the default filesystem on virtually every Windows installation) — NTFS ships with effectively every Windows deployment and Windows runs on roughly 1.4 billion active devices worldwide (~70-75% desktop OS market share), so the plausible affected installed base is the entire Windows fleet of workstations…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows NTFS Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 1909, windows 10 2004, windows 10 20h2, windows 10 21h1, windows 7, windows 8.1, windows rt 8.1, windows server 2004, windows server 2008
Weakness
CWE-191
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news