CVE-2021-31956

HIGH KEV

Microsoft Windows 10 1507 < 10.0.10240.18967 - Integer Underflow

Title source: rule

Description

Windows NTFS Elevation of Privilege Vulnerability

Exploits (5)

nomisec WORKING POC 5 stars
by Y3A · local
https://github.com/Y3A/CVE-2021-31956
nomisec WORKING POC 4 stars
by hoangprod · local
https://github.com/hoangprod/CVE-2021-31956-POC
nomisec STUB
by deletehead · poc
https://github.com/deletehead/Pool-Overflow-CVE-2021-31956
nomisec WORKING POC
by hzshang · poc
https://github.com/hzshang/CVE-2021-31956
patchapalooza WORKING POC
by aazhuliang · local
https://github.com/aazhuliang/CVE-2021-31956-EXP

Scores

CVSS v3 7.8
EPSS 0.9072
EPSS Percentile 99.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-04-14
InTheWild.io 2021-04-14
ENISA EUVD EUVD-2021-18829
CWE
CWE-191
Status published
Products (18)
microsoft/windows_10_1507 < 10.0.10240.18967
microsoft/windows_10_1607 < 10.0.14393.4467
microsoft/windows_10_1809 < 10.0.17763.1999
microsoft/windows_10_1909 < 10.0.18363.1621
microsoft/windows_10_2004 < 10.0.19041.1052
microsoft/windows_10_20h2 < 10.0.19042.1052
microsoft/windows_10_21h1 < 10.0.19043.1052
microsoft/windows_7
microsoft/windows_8.1
microsoft/windows_rt_8.1
... and 8 more
Published Jun 08, 2021
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026