Junglewise Threat Intelligence

CVE-2021-31955: Microsoft Windows Kernel Information Disclosure Vulnerability

CVE-2021-31955 · Severity: critical · CVSS 5.5 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Windows, Microsoft Windows 10, Microsoft Windows Server, Microsoft Windows Server 2019. Vendors: Microsoft.

Executive brief

An information disclosure vulnerability exists in the Microsoft Windows Kernel that allows a local attacker to read the contents of kernel memory from a user-mode process. This flaw can be used to bypass security features by exposing sensitive system information.

Affected products

  • Microsoft Windows 10 1809, 1909, 2004, 20H2, 21H1
  • Microsoft Windows Server 2019 -
  • Microsoft Windows Server 2004, 20H2

Timeline

  • 2021-06-08: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported as exploited in the wild in CISA KEV catalog

Related threats