CVE-2021-31956: Windows NTFS Elevation of Privilege Vulnerability
Published Jun 8, 2021
·Updated
Microsoft Windows New Technology File System (NTFS) contains an unspecified vulnerability that allows attackers to escalate privileges via a specially crafted application.
Other sources
Windows NTFS Elevation of Privilege Vulnerability
Affected Software
30 affected components
Microsoft Windows 10=1809
Microsoft Windows 10 1507<10.0.10240.18967
Microsoft Windows 10 1607<10.0.14393.4467
Microsoft Windows 10 1809<10.0.17763.1999
Microsoft Windows 10 1909<10.0.18363.1621
Microsoft Windows 10 2004<10.0.19041.1052
Microsoft Windows 10 20h2<10.0.19042.1052
Microsoft Windows 10 21h1<10.0.19043.1052
Microsoft Windows 7=sp1
Microsoft Windows 8.1
Microsoft Windows RT 8.1
Microsoft Windows Server 2004<10.0.19041.1052
Microsoft Windows Server 2008=r2-sp1
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2012
Microsoft Windows Server 2012=r2
Microsoft Windows Server 2016<10.0.14393.4467
Microsoft Windows Server 2019<10.0.17763.1999
Microsoft Windows Server 20h2<10.0.19042.1052
Microsoft Windows 10
Microsoft Windows 10=20h2
Microsoft Windows 10=21h1
Microsoft Windows 10=1607
Microsoft Windows 10=1909
Microsoft Windows 10=2004
Microsoft Windows Server 2016
Microsoft Windows Server 2016=20h2
Microsoft Windows Server 2016=2004
Microsoft Windows Server 2019
Microsoft Windows
Remediation
Event History
Jun 8, 2021
CVE Published
via MITRE·10:46 PM
Data Sourced
via MITRE·10:46 PM
DescriptionSeverity
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Nov 3, 2021
Known Exploited
via CISA·12:00 AM
Frequently Asked Questions
1
What is CVE-2021-31956?
CVE-2021-31956 is a vulnerability in Microsoft Windows NTFS that allows attackers to escalate privileges.
2
What software is affected by CVE-2021-31956?
Microsoft Windows 10, Windows 7, Windows 8.1, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows Server 2016, and Windows Server 2019 are affected.
3
How severe is CVE-2021-31956?
CVE-2021-31956 has a severity rating of 7.8 (critical).
4
How can I fix CVE-2021-31956?
Apply the latest security updates from Microsoft to fix CVE-2021-31956.
5
Where can I find more information about CVE-2021-31956?
You can find more information about CVE-2021-31956 on the Microsoft Security Guidance website.