⚠ Actively exploited
Added to CISA KEV on 2021-11-03. Federal agencies required to patch by 2021-11-17. Required action: Apply updates per vendor instructions..

CVE-2021-31956Integer Underflow (Wrap or Wraparound) in Microsoft Windows 10 Version 1507

Severity
7.8HIGHCNA
No vector
EPSS
90.7%
top 0.38%
CISA KEV
KEV
Added 2021-11-03
Due 2021-11-17
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJun 8
KEV addedNov 3
KEV dueNov 17
Latest updateApr 1
CISA Required Action: Apply updates per vendor instructions.

Description

Windows NTFS Elevation of Privilege Vulnerability Windows NTFS Elevation of Privilege Vulnerability

Affected Packages18 packages

CVEListV5microsoft/windows_76.1.06.1.7601.25632
CVEListV5microsoft/windows_8.16.3.06.3.9600.20045+1
CVEListV5microsoft/windows_server_20126.2.06.2.9200.23372
CVEListV5microsoft/windows_server_201610.0.010.0.14393.4467
CVEListV5microsoft/windows_server_201910.0.010.0.17763.1999

🔴Vulnerability Details

3
Project0
The More You Know, The More You Know You Don’t Know - Project Zero2022-04-01
CVEList
Windows NTFS Elevation of Privilege Vulnerability2021-06-08
VulnCheck
Microsoft Windows NTFS Privilege Escalation Vulnerability2021

📋Vendor Advisories

2
CISA
Microsoft Windows NTFS Privilege Escalation Vulnerability2021-11-03
Microsoft
Windows NTFS Elevation of Privilege Vulnerability2021-06-08

🕵️Threat Intelligence

1
Krebs
Microsoft Patches Six Zero-Day Security Holes2021-06-08
CVE-2021-31956 — Integer Underflow (Wrap or Wraparound) | cvebase