PT-2021-3303 · Microsoft · Windows Ntfs+1
CVE-2021-31956
·
Published
2021-06-08
·
Updated
2026-06-29
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Windows NTFS (affected versions not specified)
Description
An elevation of privilege issue exists in the Windows NTFS driver
ntfs.sys due to improper access control and a heap overflow. A heap overflow occurs when a program writes more data to a heap-allocated memory block than it can hold, potentially corrupting adjacent memory. Attackers can abuse this to corrupt adjacent kernel objects and create an arbitrary read/write primitive by shaping the kernel heap, which allows them to steal the SYSTEM token from another process and gain elevated privileges on the system.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
LPE
DoS
Integer Underflow
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows
Windows Ntfs