
CVE-2021-31956 is a Windows kernel privilege escalation vulnerability in NTFS ("ntfs.sys") caused by an integer underflow while processing Extended Attributes (EA). The resulting paged pool corruption can be turned into arbitrary kernel read/write primitives. What makes NCC Group's research particularly interesting is that it demonstrates exploitation without relying on the CVE-2021-31955 kernel address leak. Instead, it leverages the Windows Notification Framework (WNF) to build reliable exploitation primitives, making it an excellent study of NTFS internals, WNF, kernel pool corruption, and modern Windows exploit development.
Post summary
The passage details the technical nature of CVE‑2021‑31956 and showcases NCC Group’s exploitation approach using WNF, focusing on kernel privilege escalation mechanisms without indicating active attacks or solutions.
