PT-2021-3303 · Microsoft · Windows Ntfs+1

CVE-2021-31956

·

Published

2021-06-08

·

Updated

2026-06-29

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows NTFS (affected versions not specified)
Description An elevation of privilege issue exists in the Windows NTFS driver ntfs.sys due to improper access control and a heap overflow. A heap overflow occurs when a program writes more data to a heap-allocated memory block than it can hold, potentially corrupting adjacent memory. Attackers can abuse this to corrupt adjacent kernel objects and create an arbitrary read/write primitive by shaping the kernel heap, which allows them to steal the SYSTEM token from another process and gain elevated privileges on the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

DoS

Integer Underflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03077
CVE-2021-31956

Affected Products

Windows
Windows Ntfs