CVE-2021-31958
published 2021-06-08CVE-2021-31958: Windows NTLM Elevation of Privilege Vulnerability Windows NTLM Elevation of Privilege Vulnerability
high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.66%
84.0th percentile
Windows NTLM Elevation of Privilege Vulnerability
Windows NTLM Elevation of Privilege Vulnerability
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_version_1507 | >= 10.0.0 < 10.0.10240.18967 | 10.0.10240.18967 |
| microsoft | windows_10_version_1607 | >= 10.0.0 < 10.0.14393.4467 | 10.0.14393.4467 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.1999 | 10.0.17763.1999 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.1621 | 10.0.18363.1621 |
| microsoft | windows_10_version_2004 | >= 10.0.0 < 10.0.19041.1052 | 10.0.19041.1052 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1052 | 10.0.19042.1052 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1052 | 10.0.19043.1052 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.25632 | 6.1.7601.25632 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.25632 | 6.1.7601.25632 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20045 | 6.3.9600.20045 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20044 | 6.3.9600.20044 |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.0.0 < 6.1.7601.25632 | 6.1.7601.25632 |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.0 < 6.1.7601.25632 | 6.1.7601.25632 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.0 < 6.0.6003.21137 | 6.0.6003.21137 |
| microsoft | windows_server_2012 | >= 6.2.0 < 6.2.9200.23372 | 6.2.9200.23372 |
| microsoft | windows_server_2012_r2 | >= 6.3.0 < 6.3.9600.20045 | 6.3.9600.20045 |
| microsoft | windows_server_2012_r2 | >= 6.3.0 < 6.3.9600.20044 | 6.3.9600.20044 |
| microsoft | windows_server_2016 | >= 10.0.0 < 10.0.14393.4467 | 10.0.14393.4467 |
| microsoft | windows_server_2019 | >= 10.0.0 < 10.0.17763.1999 | 10.0.17763.1999 |
| microsoft | windows_server_version_2004 | >= 10.0.0 < 10.0.19041.1052 | 10.0.19041.1052 |
| microsoft | windows_server_version_20h2 | >= 10.0.0 < 10.0.19042.1052 | 10.0.19042.1052 |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_1909 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
cvelistv57.5HIGH
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CVEList
Windows NTLM Elevation of Privilege Vulnerability
cvelistv5·2021-06-08·CVSS 7.5
CVE-2021-31958 [HIGH] Windows NTLM Elevation of Privilege Vulnerability
Windows NTLM Elevation of Privilege Vulnerability
Windows NTLM Elevation of Privilege Vulnerability
Microsoft
Windows NTLM Elevation of Privilege Vulnerability
vendor_msrc·2021-06-08·CVSS 7.5
CVE-2021-31958 [HIGH] Windows NTLM Elevation of Privilege Vulnerability
Windows NTLM Elevation of Privilege Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
This vulnerability requires that a user with an affected version of Windows access a malicious server. An attacker would have to host a specially crafted server share or website. An attacker would have no way to force users to visit this specially crafted server share or website, but would have to convince them to visit the server share or website, typically by way of an enticement in an email or chat message.
Windows NTLM: Windows NTLM
Microsoft: Microsoft
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation
No detection rules found.
No public exploits indexed.
2021-06-08
Published