ZeroHour

CVE-2021-31979

KEVmass

Local Privilege Escalation in Microsoft Windows Kernel (CVE-2021-31979)

CISA: Microsoft Windows Kernel Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
5%p91
Published
()
KEV added
AI analysis

CVE-2021-31979 is an elevation-of-privilege vulnerability in the Microsoft Windows kernel caused by improper handling of objects in memory (CWE-119), rated 7.8 (high) with local attack vector, low privileges required, and no user interaction. An attacker who already has limited privileges on a machine can trigger the flaw with specially crafted code, gaining code execution in kernel/SYSTEM context and full control of the host. It is most dangerous when chained with a remote code execution bug to move from a network foothold to SYSTEM — the pattern reported in the July 2021 spyware campaign linked to the Israeli surveillance vendor Candiru. Any organization running the affected Windows 10 versions (1507 through 21H1), Windows 7, Windows 8.1/RT 8.1, or Windows Server 2004/2008 is exposed. The flaw was fixed in Microsoft's July 2021 Patch Tuesday release, was exploited in the wild, and was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with the required action of applying vendor updates.

What to do: Apply Microsoft's July 2021 (or later cumulative) Windows security updates to every affected Windows 10, 7, 8.1, RT 8.1, and Server 2004/2008 system — this is the CISA-required action, and no public PoC or workaround is known, so patching is the primary mitigation. Prioritize user-facing workstations and any Windows host where unprivileged users can run code, since this local flaw is commonly chained with a remote code execution bug. Verify patch levels against the July 2021 release and review hosts that missed it for signs of the Candiru-linked spyware activity reported at the time.

Affected
microsoft Windows 101507, 1607, 1809, 1909, 2004, 20H2, 21H1
microsoft Windows 7
microsoft Windows 8.1
microsoft Windows RT 8.1
microsoft Windows Server 2004
microsoft Windows Server 2008
Estimated exposure
masshundreds of millions of Windows endpoints (Windows runs on 1B+ devices; the affected version list spanned nearly the entire Windows install base at disclosure) — Estimated from the Windows desktop installed base (over 1 billion devices) and the breadth of the affected versions, which covered all major supported Windows 10 branches plus Windows 7, 8.1/RT 8.1, and Server 2004/2008 at the time of the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Kernel Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 1909, windows 10 2004, windows 10 20h2, windows 10 21h1, windows 7, windows 8.1, windows rt 8.1, windows server 2004, windows server 2008
Weakness
CWE-119
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news