PT-2021-3303 · Microsoft · Windows Ntfs+1

Published

2021-06-08

·

Updated

2026-06-15

·

CVE-2021-31956

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows NTFS (affected versions not specified)
Description An elevation of privilege issue exists in the ntfs.sys driver due to improper access control. The flaw involves a heap overflow—a condition where data exceeds the allocated memory buffer on the heap—which allows the corruption of adjacent kernel objects. By manipulating the kernel heap, an attacker can create an arbitrary read/write primitive to steal a SYSTEM token from another process, thereby gaining elevated privileges on the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

LPE

Buffer Overflow

Integer Underflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03077
CVE-2021-31956

Affected Products

Windows
Windows Ntfs