EXPOSURES › CVE-2021-31979
CVE-2021-31979
HIGH ⌖ ON CISA KEV · EXPLOITEDAn unpatched Windows kernel privilege escalation vulnerability was actively exploited in the wild, allowing attackers to escalate privileges without remote code execution.
This unpatched kernel vulnerability (CVE-2021-31979) was listed in CISA's KEV catalog, indicating active exploitation. For DIB organizations, this means systems running unpatched Windows are at risk of privilege escalation, which can lead to data exfiltration or lateral movement. The key takeaway is to ensure all Windows systems are patched promptly and monitor for signs of exploitation.
Shame score — The vulnerability was unpatched and actively exploited in the wild, demonstrating a failure to patch known vulnerabilities and leaving systems vulnerable to attackers.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
"Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation."
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |