CVE-2021-31979
KEVmassLocal Privilege Escalation in Microsoft Windows Kernel (CVE-2021-31979)
CISA: Microsoft Windows Kernel Privilege Escalation Vulnerability
CVE-2021-31979 is an elevation-of-privilege vulnerability in the Microsoft Windows kernel caused by improper handling of objects in memory (CWE-119), rated 7.8 (high) with local attack vector, low privileges required, and no user interaction. An attacker who already has limited privileges on a machine can trigger the flaw with specially crafted code, gaining code execution in kernel/SYSTEM context and full control of the host. It is most dangerous when chained with a remote code execution bug to move from a network foothold to SYSTEM — the pattern reported in the July 2021 spyware campaign linked to the Israeli surveillance vendor Candiru. Any organization running the affected Windows 10 versions (1507 through 21H1), Windows 7, Windows 8.1/RT 8.1, or Windows Server 2004/2008 is exposed. The flaw was fixed in Microsoft's July 2021 Patch Tuesday release, was exploited in the wild, and was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with the required action of applying vendor updates.
What to do: Apply Microsoft's July 2021 (or later cumulative) Windows security updates to every affected Windows 10, 7, 8.1, RT 8.1, and Server 2004/2008 system — this is the CISA-required action, and no public PoC or workaround is known, so patching is the primary mitigation. Prioritize user-facing workstations and any Windows host where unprivileged users can run code, since this local flaw is commonly chained with a remote code execution bug. Verify patch levels against the July 2021 release and review hosts that missed it for signs of the Candiru-linked spyware activity reported at the time.
| microsoft Windows 10 | 1507, 1607, 1809, 1909, 2004, 20H2, 21H1 |
| microsoft Windows 7 | — |
| microsoft Windows 8.1 | — |
| microsoft Windows RT 8.1 | — |
| microsoft Windows Server 2004 | — |
| microsoft Windows Server 2008 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows Kernel Elevation of Privilege Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 1909, windows 10 2004, windows 10 20h2, windows 10 21h1, windows 7, windows 8.1, windows rt 8.1, windows server 2004, windows server 2008
- Weakness
- CWE-119
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H