CVE-2021-31956
Microsoft Windows NTFS Privilege Escalation Vulnerability
Description
CVE-2021-31956 is a HIGH vulnerability affecting Microsoft Windows, carrying a CVSS 3.1 score of 7.8. Microsoft Windows New Technology File System (NTFS) contains an unspecified vulnerability that allows attackers to escalate privileges via a specially crafted application. This CVE is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of 2021-11-17. With an EPSS score of 0.88708 (99.51th percentile), this vulnerability demonstrates significant real-world exploitation activity and should be prioritized for immediate remediation.
KEV Information
CVSS Score
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| microsoft | windows 10 1507 | < 10.0.10240.18967 |
| microsoft | windows 10 1607 | < 10.0.14393.4467 |
| microsoft | windows 10 1809 | < 10.0.17763.1999 |
| microsoft | windows 10 1909 | < 10.0.18363.1621 |
| microsoft | windows 10 2004 | < 10.0.19041.1052 |
| microsoft | windows 10 20h2 | < 10.0.19042.1052 |
| microsoft | windows 10 21h1 | < 10.0.19043.1052 |
| microsoft | windows 7 | - |
| microsoft | windows 8.1 | - |
| microsoft | windows rt 8.1 | - |
| microsoft | windows server 2004 | < 10.0.19041.1052 |
| microsoft | windows server 2008 | r2; sp2 |
| microsoft | windows server 2012 | -; r2 |
| microsoft | windows server 2016 | < 10.0.14393.4467 |
| microsoft | windows server 2019 | < 10.0.17763.1999 |
| microsoft | windows server 20h2 | < 10.0.19042.1052 |
Multiple CVSS Assessments
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-31956(Patch, Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-31956(US Government Resource)
Weakness Type
CWE-191: Integer Underflow (Wrap or Wraparound)
CVE-2021-31956 is classified under CWE-191 — Integer Underflow (Wrap or Wraparound). Integer Underflow occurs when an arithmetic subtraction operation produces a result that is less than the minimum value that can be stored in the target integer type, causing the value to "wrap around" to a large positive number (for unsigned) or to the maximum positive value (for signed integers). For example, subtracting 1 from an unsigned zero produces the maximum unsigned value (e.g., 4294967295 for 32-bit). Integer underflows are particularly dangerous when the resulting large value is used for buffer allocation, loop counters, or array indices, often leading to buffer overflows or denial of service.
In the context of Microsoft Windows, this weakness is particularly concerning because Integer underflow vulnerabilities can have severe security consequences. When an underflowed value is used as a buffer size, it results in massive allocations that cause memory exhaustion or subsequent buffer overflows. Organizations using affected versions should understand that this vulnerability class has historically enabled severe compromises across enterprise environments.
Learn more: CWE-191 — Integer Underflow (Wrap or Wraparound)
Impact Analysis
CVE-2021-31956 carries a CVSS 3.1 score of 7.8 (HIGH) with Unchanged Scope.
Confidentiality (HIGH): Successful exploitation grants the attacker extensive access to sensitive data processed by Microsoft Windows, including configuration files, credentials, and potentially data from connected systems.
Integrity (HIGH): Attackers can modify critical system files, install backdoors, alter configurations, or deploy malware on affected systems running Microsoft Windows.
Availability (HIGH): Complete disruption of the affected service or system is possible, including denial of service, system crashes, or rendering the product inoperable.
Scope Unchanged: The vulnerability's scope is Unchanged (U), meaning exploitation is contained within the vulnerable component. The impact, while significant, is limited to the Microsoft Windows environment itself.
With an EPSS score of 0.88708 (99.51th percentile), this vulnerability ranks among the most likely to be exploited in real-world attacks, underscoring the urgency of remediation.
Exploit Maturity
CVE-2021-31956 has confirmed active exploitation in the wild and is listed in CISA's Known Exploited Vulnerabilities catalog.
Exploit status: This vulnerability has been actively exploited, as confirmed by its inclusion in the KEV catalog. The EPSS score of 0.88708 (99.51th percentile) places it among the most exploited vulnerabilities tracked.
Ransomware association: As of the latest KEV data, no direct ransomware association has been confirmed for CVE-2021-31956. However, the confirmed exploitation in the wild means threat actors are actively using this vulnerability in attacks.
Attack surface: The local attack vector means an attacker needs local access or must trick a user into running malicious content on the affected system. No user interaction is required once local access is obtained.
KEV deadline: CISA required federal agencies to remediate this vulnerability by 2021-11-17. All organizations should treat this deadline as a strong recommendation for their own remediation timelines.
Remediation
- Apply vendor patches immediately. Apply updates per vendor instructions. Consult the vendor advisory at portal.msrc.microsoft.com for specific patch guidance.
- Verify affected product versions in your environment. Identify all instances of Microsoft Windows in your infrastructure. Use asset inventory and vulnerability scanning tools to ensure no instances are missed.
- Implement interim mitigations if patching is delayed. If immediate patching is not feasible, apply network-level controls such as restricting access to the affected component, enabling enhanced logging, and monitoring for indicators of compromise.
- Scan for signs of prior exploitation. Given the confirmed active exploitation of this vulnerability, review system logs and security monitoring data for evidence of compromise. Conduct a thorough investigation if any suspicious activity is detected.
- Update detection signatures and monitoring rules. Ensure intrusion detection and prevention systems, endpoint detection tools, and SIEM rules are updated to detect exploitation attempts targeting CVE-2021-31956.
- Conduct a post-remediation review. After patching, verify the fix is effective and document the remediation actions taken. Update your vulnerability management records and assess whether any additional hardening measures are warranted.
Technical Details
CVE-2021-31956 is a HIGH-severity vulnerability in Microsoft Windows that requires local access to the target system for exploitation. The attack complexity is low, meaning no specialized conditions or preparation are required beyond the attack prerequisites. The attacker requires low-level privileges on the target system. No user interaction is required, allowing fully automated exploitation once access is obtained.
Technical mechanism: Windows NTFS Elevation of Privilege Vulnerability. The underlying flaw relates to Integer Underflow (Wrap or Wraparound), where Integer Underflow occurs when an arithmetic subtraction operation produces a result that is less than the minimum value that can be stored in the target integer type, causing the value to "wrap around" to a large positive number (for unsigned) or to the maximum positive value (for signed integers). For example, subtracting 1 from an unsigned zero produces the maximum unsigned value (e.g., 4294967295 for 32-bit).
CVSS 3.1 vector analysis: The vector reflects an Attack Vector of LOCAL, Attack Complexity of LOW, Privileges Required of LOW, User Interaction of NONE, Scope UNCHANGED, and impact ratings of HIGH/HIGH/HIGH for Confidentiality/Integrity/Availability respectively. The Unchanged scope means impact is contained within the vulnerable component itself.
Frequently Asked Questions
Is CVE-2021-31956 being actively exploited?
Yes, CVE-2021-31956 is confirmed to be actively exploited in the wild. It is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, which means federal agencies were required to remediate it by 2021-11-17. While no direct ransomware association has been confirmed, active exploitation is ongoing. The EPSS score of 0.88708 (99.51th percentile) further confirms significant exploitation activity.
Which products are affected by CVE-2021-31956?
This vulnerability affects Microsoft Windows. Organizations running affected versions should verify their exposure and prioritize remediation. Check vendor advisories for the complete and most current list of affected versions.
How do I fix CVE-2021-31956?
Apply updates per vendor instructions. Ensure all affected instances of Microsoft Windows are identified using vulnerability scanning and asset management tools. If immediate patching is not possible, implement network-level mitigations and enhanced monitoring. After patching, verify the fix and scan for indicators of prior compromise.
How severe is CVE-2021-31956?
CVE-2021-31956 is rated HIGH with a CVSS 3.1 score of 7.8. Its EPSS score of 0.88708 places it in the 99.51th percentile for exploitation likelihood. The vulnerability has confirmed active exploitation in the wild and was required to be remediated by federal agencies by 2021-11-17 per CISA's KEV directive.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.