CVE-2021-31979KEV · OVERDUECWE-119

Microsoft Windows Kernel Privilege Escalation Vulnerability

High · published July 14, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it high at 7.8. It is confirmed in active exploitation. It sits in the 90.9th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
7.8
EPSS
5%
Percentile
90.9
In the wild
Confirmed
What it is

⚡ An elevation of privilege vulnerability in the Windows Kernel is making waves, and attackers are eyeing it like a kid in a candy store! Think of it as a backstage pass to a concert. While regular ticket holders can see the show, an attacker exploiting this flaw can stroll right into the VIP area, accessing all the goodies without permission! If successfully exploited, a malicious actor could gain higher-level access, allowing them to modify system settings, install malicious software, or even take complete control of the system. It's the digital equivalent of someone sneaking into the tech command center and having the ability to pull all the strings!

Put simply

Think of it as a backstage pass to a concert. While regular ticket holders can see the show, an attacker exploiting this flaw can stroll right into the VIP area, accessing all the goodies without permission! This vulnerability resides in the Windows Kernel, where it fails to properly handle objects in memory. This allows a user to elevate their privileges, gaining unauthorized access to sensitive system functions.

What to do

If successfully exploited, a malicious actor could gain higher-level access, allowing them to modify system settings, install malicious software, or even take complete control of the system. It's the digital equivalent of someone sneaking into the tech command center and having the ability to pull all the strings! Immediate actions include applying the latest security patch from Microsoft to remedy this vulnerability. Also, ensure that you have a robust security policy in place, including regular system updates and monitoring for suspicious activity. You've got this! With a swift update and vigilant practices, you'll be securing your system in no time! 🛡️

The record
Technical detail
CVSS v3.1
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.04540 · 90.9th percentile
Weakness
CWE-119 · Improper Restriction of Operations within the Bounds of a Memory Buffer
Published
2021-07-14T22:15Z
KEV added
2021-11-03 · due 2021-11-17
Affected products (18)
ProductVersionsFixed in
microsoft/windows_10_1507< 10.0.10240.1900310.0.10240.19003
microsoft/windows_10_1607< 10.0.14393.453010.0.14393.4530
microsoft/windows_10_1809< 10.0.17763.206110.0.17763.2061
microsoft/windows_10_1909< 10.0.18363.167910.0.18363.1679
microsoft/windows_10_2004< 10.0.19041.111010.0.19041.1110
microsoft/windows_10_20h2< 10.0.19042.111010.0.19042.1110
microsoft/windows_10_21h1< 10.0.19043.111010.0.19043.1110
microsoft/windows_7all versions
microsoft/windows_8.1all versions
microsoft/windows_rt_8.1all versions
microsoft/windows_server_2004< 10.0.19041.111010.0.19041.1110
microsoft/windows_server_2008all versions
microsoft/windows_server_2008all versions
microsoft/windows_server_2012all versions
microsoft/windows_server_2012all versions
microsoft/windows_server_2016< 10.0.14393.453010.0.14393.4530
microsoft/windows_server_2019< 10.0.17763.206110.0.17763.2061
microsoft/windows_server_20h2< 10.0.19042.111010.0.19042.1110
References (3)
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 14 JUL 17:53Z
    Windows Kernel Elevation of Privilege Vulnerability
    cvelistv5