Executive brief
Microsoft Windows NTFS contains an integer underflow vulnerability (CWE-191) that allows for local elevation of privilege. An attacker with low privileges can exploit this via a specially crafted application to gain high-level system access.
Affected products
- Microsoft Windows 10 1507, 1607, 1809, 1909, 2004, 20H2, 21H1
- Microsoft Windows Server 2008, 2012, 2016, 2019, 2004, 20H2
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1 -
- Microsoft Windows RT 8.1 -
Timeline
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: disclosed