CVE-2021-31955General(microsoft / windows_10_1809)

LOWCVSS 5.5 · MEDIUMCISA KEV

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Windows Kernel Information Disclosure Vulnerability

0.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2021-11-17. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-497

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1809
  • windows_10_1909
  • windows_10_2004
  • windows_10_20h2

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
windows_10_1809windows_10_1909windows_10_2004windows_10_20h2windows_10_21h1windows_server_2004windows_server_2019windows_server_20h2

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-29: 1Technical Details · 2026-06-29: 106-29
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • OS Dev@OSdev_
    General

    CVE-2021-31956 is a Windows kernel privilege escalation vulnerability in NTFS ("ntfs.sys") caused by an integer underflow while processing Extended Attributes (EA). The resulting paged pool corruption can be turned into arbitrary kernel read/write primitives. What makes NCC Group's research particularly interesting is that it demonstrates exploitation without relying on the CVE-2021-31955 kernel address leak. Instead, it leverages the Windows Notification Framework (WNF) to build reliable exploitation primitives, making it an excellent study of NTFS internals, WNF, kernel pool corruption, and modern Windows exploit development.

    Post summary

    The passage details the technical nature of CVE‑2021‑31956 and showcases NCC Group’s exploitation approach using WNF, focusing on kernel privilege escalation mechanisms without indicating active attacks or solutions.

    19053133.5K
    5.0K followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1809---
OSmicrosoftwindows_10_1909---
OSmicrosoftwindows_10_2004---
OSmicrosoftwindows_10_20h2---
OSmicrosoftwindows_10_21h1---
OSmicrosoftwindows_server_2004---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_20h2---

Explore more