Skip to content
COOEY

EXPOSURES › CVE-2021-31956

CVE-2021-31956

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-31956 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatchedprivilege-escalation

An unpatched privilege escalation flaw in Windows NTFS allowed attackers to gain elevated access via a crafted application.

This unpatched vulnerability in Windows NTFS enabled privilege escalation, allowing attackers to execute arbitrary code with elevated privileges. For DIB organizations, this represents a critical compliance gap under NIST 800-171, as it violates the requirement to patch known vulnerabilities and maintain system integrity. Organizations must ensure all Windows systems are updated promptly and monitor for exploitation attempts.

Shame score — The vulnerability remained unpatched long enough to be added to CISA's KEV catalog, indicating a failure to address a known, exploitable flaw that could lead to system compromise.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Windows New Technology File System (NTFS) contains an unspecified vulnerability that allows attackers to escalate privileges via a specially crafted application.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
Widespread acknowledgement of a significant vulnerability, with minimal positive commentary.
cooey ↗ severe-fallout -0.80
Neutral reporting of the vulnerability.
"Microsoft Windows New Technology File System (NTFS) contains an unspecified vulnerability that allows attackers to escalate privileges via a specially crafted application."
app.opencve.io ↗ severe-fallout +0.00
Listing of the CVE alongside other vulnerabilities.
"CVE-2026-62870 1 Microsoft 5 365 Apps , Excel 2016 , Office 2019 and 2 more"
app.opencve.io ↗ severe-fallout +0.00
Listing of the CVE alongside other vulnerabilities.
"CVE-2026-60586 1 Oracle 3 Mysql Connector/j , Mysql Connector/j , Mysql Connectors"
www.cvefind.com ↗ severe-fallout +0.00
Listing of the CVE alongside other vulnerabilities.
"CVE 2026 CVE Statistics"
xposedornot.com ↗ severe-fallout +0.00
No mention of the CVE.
"Browse 772 breaches across 20 industries."
www.jcpenney.com ↗ severe-fallout +0.00
No mention of the CVE.
"JCPenney: Clothing, Bed & Bath, Home Decor, Jewelry & Beauty"
AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized