CVE-2021-31955KEV · OVERDUE

Windows Kernel Information Disclosure Vulnerability

Medium · published June 8, 2021

Patch now

The score understates this — it's already being exploited

CVSS calls it medium at 5.5. It is confirmed in active exploitation. It sits in the 99.6th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
5.5
EPSS
81%
Percentile
99.6
In the wild
Confirmed
What it is

⚠️ Windows Kernel is spilling secrets! This information disclosure vulnerability could let attackers peek at sensitive data without breaking a sweat. 🔍 Think of it like a hotel manager accidentally leaving a stack of guest records on the front desk — anyone walking by could just glance at them without even trying. That's how easily this bug can expose information to a determined threat actor. An attacker could exploit this flaw to access sensitive information stored in the kernel, potentially leading to unauthorized system access or elevated privileges. While not catastrophic, the consequences could still be quite troubling, allowing attackers to gather intelligence for further attacks.

Put simply

Think of it like a hotel manager accidentally leaving a stack of guest records on the front desk — anyone walking by could just glance at them without even trying. That's how easily this bug can expose information to a determined threat actor. This vulnerability stems from improper handling of memory in the Windows Kernel, which allows an attacker to leverage this weakness for information disclosure without requiring authentication.

What to do

An attacker could exploit this flaw to access sensitive information stored in the kernel, potentially leading to unauthorized system access or elevated privileges. While not catastrophic, the consequences could still be quite troubling, allowing attackers to gather intelligence for further attacks. To protect your systems, ensure you apply the latest Microsoft patches that address this vulnerability. Regularly review system configurations and restrict access to sensitive areas of your network. Staying proactive is key! You can tackle this! Stay vigilant and follow these steps to keep your systems secure. 🛡️

The record
Technical detail
CVSS v3.1
5.5 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:F/RL:O/RC:C
CVSS v4.0
Not supplied
EPSS
0.81107 · 99.6th percentile
Published
2021-06-08T22:46Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 08 JUN 22:46Z
    Windows Kernel Information Disclosure Vulnerability
    cvelistv5