CVE-2021-31954
published 2021-06-08CVE-2021-31954: Windows Common Log File System Driver Elevation of Privilege Vulnerability
high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.0 < 10.0.10240.18967 | 10.0.10240.18967 |
| microsoft | windows_10_version_1607 | >= 10.0.0 < 10.0.14393.4467 | 10.0.14393.4467 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.1999 | 10.0.17763.1999 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.1621 | 10.0.18363.1621 |
| microsoft | windows_10_version_2004 | >= 10.0.0 < 10.0.19041.1052 | 10.0.19041.1052 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1052 | 10.0.19042.1052 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1052 | 10.0.19043.1052 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.25632 | 6.1.7601.25632 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.25632 | 6.1.7601.25632 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20045 | 6.3.9600.20045 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20044 | 6.3.9600.20044 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.0.0 < 6.1.7601.25632 | 6.1.7601.25632 |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.0 < 6.1.7601.25632 | 6.1.7601.25632 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.0 < 6.0.6003.21137 | 6.0.6003.21137 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.0 < 6.2.9200.23372 | 6.2.9200.23372 |
| microsoft | windows_server_2012_r2 | >= 6.3.0 < 6.3.9600.20045 | 6.3.9600.20045 |
| microsoft | windows_server_2012_r2 | >= 6.3.0 < 6.3.9600.20044 | 6.3.9600.20044 |
| microsoft | windows_server_2016 | — | — |
GHSA
GHSA-w458-qg9w-x8vm: Windows Common Log File System Driver Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-31954 [HIGH] CWE-122 GHSA-w458-qg9w-x8vm: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Microsoft
Windows Common Log File System Driver Elevation of Privilege Vulnerability
vendor_msrc·2021-06-08·CVSS 7.8
CVE-2021-31954 [HIGH] Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver: Windows Common Log File System Driver
Microsoft: Microsoft
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation More Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5003646
Reference: https://support.microsoft.com/help/5003646
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5003635
Reference: https://support.microsoft.com/help/5003635
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5003637
Reference: https://support.microsoft.com/help/5003637
Reference: https://catalog.
No detection rules found.
No public exploits indexed.
Qualys
Microsoft & Adobe Patch Tuesday (June 2021) – Microsoft 50 Vulnerabilities with 5 Critical, Adobe 21 Critical Vulnerabilities
blogs_qualys·2021-06-08·CVSS 5.2
CVE-2021-31985 [MEDIUM] Microsoft & Adobe Patch Tuesday (June 2021) – Microsoft 50 Vulnerabilities with 5 Critical, Adobe 21 Critical Vulnerabilities
## Microsoft Patch Tuesday – June 2021
Microsoft patched 50 CVEs in their June 2021 Patch Tuesday release, and five of them are rated as critical severity. Six have applicable exploits.
## Critical Microsoft Vulnerabilities Patched
CVE-2021-31985 – Microsoft Defender Remote Code Execution Vulnerability
Microsoft released patches addressing a critical RCE vulnerability in its Defender product (CVE-2021-31985). This CVE has a high likelihood of exploitability and is assigned a CVSSv3 base score of 7.8 by the vendor.
CVE-2021-31959 – Scripting Engine Memory Corruption Vulnerability
Microsoft released patches addressing a critical memory corruption vulnerability in the Chakra JScript scripting engine. This vulnerability impacts Windows RT, Windows 7, Windows 8, Windows 10, Windows Server
Zscaler
Zscaler found Windows Vulnerabilities | 06-08-2021
blogs_zscaler·CVSS 5.5
[MEDIUM] Zscaler found Windows Vulnerabilities | 06-08-2021
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
2021-06-08
Published