← back
CVE-2021-31956

Windows NTFS Elevation of Privilege Vulnerability

CVSS 7.8 HIGHEPSS 20.3%● KEVCWE-191
In short

A flaw in Windows NTFS file system allows a local attacker to gain higher privileges on the system. An attacker who already has access to a user account can exploit this vulnerability to gain administrator-level permissions.

Technical detail

This integer underflow vulnerability in the Windows NTFS driver allows a local, authenticated attacker to escalate privileges through specially crafted file operations. The attack requires existing user-level access and results in kernel-mode code execution with SYSTEM privileges.

Summary generated and translated by AI from the official description.
Windows NTFS Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →