LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-31979: Microsoft Windows Kernel Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-31979 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.

CVE-2021-31979 is a privilege-escalation vulnerability in the Microsoft Windows kernel. An attacker who already has some level of access on a system could use it to gain higher privileges. Because the kernel sits at the core of the operating system, successful abuse can let an adversary take fuller control of the host, which is why Windows administrators and security teams treat kernel elevation flaws as high priority.

Public detail on the exact trigger is limited; CISA describes it only as an unspecified kernel vulnerability that allows privilege escalation. Confirm all version, patch, and configuration specifics directly against the Microsoft advisory before acting.

How it works

The weakness is classified as CWE-119 (improper restriction of operations within the bounds of a memory buffer). In kernel code this class of flaw typically means a buffer is read from or written to outside its intended bounds. An attacker who can reach the vulnerable kernel path may corrupt adjacent memory structures that the kernel uses for security decisions, such as process tokens or privilege bits.

Abuse therefore requires the attacker first to obtain code execution or a foothold in a less-privileged context on the same machine. From there the attacker crafts input that exercises the out-of-bounds condition, aiming to elevate to SYSTEM or an equivalent high-integrity level. Exact exploit mechanics are not published in the supplied facts; treat any public proof-of-concept claims with caution and validate them only against vendor or trusted researcher analysis.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows. Kernel components ship with every supported Windows client and server edition, so any Windows host is potentially in scope until the vendor update is confirmed installed.

If your inventory tooling cannot map builds to the CVE, treat every unpatched Windows host as potentially affected until you verify otherwise with the vendor advisory.

How to remediate

Apply the security update Microsoft released for CVE-2021-31979. CISA’s required action is simply to apply updates per vendor instructions. Use your normal patch-deployment pipeline (WSUS, Microsoft Endpoint Configuration Manager, Intune, or equivalent) and verify installation by checking the resulting OS build number or the presence of the specific knowledge-base article listed in the advisory.

If you can't patch immediately

When immediate patching is blocked by change freezes or compatibility testing, reduce the attack surface until the update can be applied:

These steps are compensating controls only; they do not eliminate the vulnerability. Schedule the official Microsoft update as soon as operationally feasible.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities are frequently used after an initial intrusion to deepen access and move laterally, which can lead to data theft or ransomware. The supplied facts do not document ransomware use specifically for CVE-2021-31979, but any confirmed compromise should still be treated as a potential breach. Review endpoint and identity logs for signs of post-exploitation activity, reset credentials for affected accounts, and follow your incident-response plan. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether those identities have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-119
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities