EXPOSURES › CVE-2021-31955
CVE-2021-31955
HIGH ⌖ ON CISA KEV · EXPLOITEDA Windows kernel vulnerability allowed attackers to read kernel memory from user mode, exposing sensitive data.
This kernel information disclosure flaw let adversaries access protected memory, potentially leaking credentials or secrets. DIBs must ensure rapid patching of Windows systems and monitor for memory-dumping malware. The failure is avoidable through timely updates and highlights the risk of unpatched OS vulnerabilities.
Shame score — A known kernel vulnerability was actively exploited in the wild, indicating a failure to patch or defend against a critical flaw.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Kernel contains an unspecified vulnerability that allows for information disclosure. Successful exploitation allows attackers to read the contents of kernel memory from a user-mode process.
"Microsoft Windows Kernel contains an unspecified vulnerability that allows for information disclosure. Successful exploitation allows attackers to read the contents of kernel memory from a user-mode process."
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |