LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-31955: Microsoft Windows Kernel Information Disclosure Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-31955 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows Kernel contains an unspecified vulnerability that allows for information disclosure. Successful exploitation allows attackers to read the contents of kernel memory from a user-mode…

CVE-2021-31955 is an information-disclosure vulnerability in the Microsoft Windows kernel. It lets a local attacker running code in user mode read contents of kernel memory. That kind of leak can expose sensitive system state and help an attacker plan further privilege escalation or persistence. Public detail on exact mechanics is limited; treat the Microsoft advisory as the authoritative source.

CISA notes that successful exploitation allows attackers to read kernel memory from a user-mode process. Ransomware use is not documented for this CVE. The required action is to apply updates per vendor instructions.

How it works

The weakness is classed as CWE-497: exposure of sensitive system information to an unauthorized control sphere. In practical terms, the Windows kernel fails to properly restrict what a user-mode process can observe. An attacker who can already execute code on the host (for example via a malicious binary, script, or compromised account) abuses that gap to pull data out of kernel address space that should remain inaccessible.

Kernel memory can contain pointers, object layouts, credentials material, or other internal state. Even without a full remote code-execution chain, the disclosed information reduces the work needed for follow-on attacks. Exact trigger conditions, IOCTLs, or structures involved are not specified in the public summary; confirm those details against the vendor advisory rather than assuming a particular exploit path.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows. It is relevant anywhere the Windows kernel is running: workstations, servers, virtual machines, and cloud instances based on Windows. Inventory every Windows host in your environment, including domain controllers, jump boxes, VDI pools, and build agents.

If your scanner or Microsoft’s own tools flag the CVE as applicable, assume the host needs the update until you verify otherwise.

How to remediate

Patch first. Apply the security updates Microsoft released for this vulnerability, following the vendor’s instructions exactly. Use your standard deployment ring (test, then pilot, then broad) but prioritize hosts that allow local code execution by multiple users or that hold high-value data.

If you can't patch immediately

When immediate patching is blocked by change windows or compatibility testing, reduce the attack surface until the update can be applied.

If your data may have been exposed

Actively exploited kernel vulnerabilities can be a stepping stone into broader compromise even when ransomware use is not documented for the specific CVE. If you have evidence of exploitation or of suspicious local code execution on unpatched hosts, follow your incident-response process: isolate affected systems, preserve memory and disk evidence, rotate credentials that may have been present in memory, and check for lateral movement.

As a quick additional check, you can run a free exposure scan of your email addresses against known breach data to see whether your accounts already appear in public breach corpora, then tighten passwords and MFA accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-497
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities