HIGH
CVE-2021-31979
CVSS
7.8
KEV
Description
Windows Kernel Elevation of Privilege Vulnerability
Summary dbcve.org
This is a Windows Kernel elevation of privilege vulnerability. The vulnerability allows a local attacker to gain elevated system privileges by exploiting a flaw in the Windows kernel. Such kernel-level EoP vulnerabilities typically arise from improper input validation, memory corruption, or race conditions in privileged code paths.
Mitigation
Apply the Microsoft security update KB5003637 (June 2021 Patch Tuesday) or subsequent relevant patches to address the kernel vulnerability. Prioritize patching systems where untrusted users have local access.
Weakness (CWE)
CWE-119
Memory Buffer Bounds Error
EPSS Score
4.54%
Probability of exploitation in next 30 days
91.2th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-31979
Patch, Vendor Advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-31979
Patch, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-31979
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.