← Back to browse · API

CVE-2021-31955

Severity
MEDIUM
CVSS
5.5
EPSS
0.81107
Risk score
75.39
CISA KEV
Yes
PoC
No
Published
2021-11-03
Modified
2021-11-03
First seen
2026-08-07
Aliases
EUVD-2021-18828, GHSA-4GRG-84CR-6C2H
Products
Microsoft:Windows, Microsoft:Windows 10 Version 1809 10.0.0 <10.0.17763.1999, Microsoft:Windows 10 Version 1909 10.0.0 <10.0.18363.1621, Microsoft:Windows 10 Version 2004 10.0.0 <10.0.19041.1052, Microsoft:Windows 10 Version 20H2 10.0.0 <10.0.19042.1052, Microsoft:Windows 10 Version 21H1 10.0.0 <10.0.19043.1052, Microsoft:Windows Server 2019 (Server Core installation) 10.0.0 <10.0.17763.1999, Microsoft:Windows Server 2019 10.0.0 <10.0.17763.1999, Microsoft:Windows Server version 2004 10.0.0 <10.0.19041.1052, Microsoft:Windows Server version 20H2 10.0.0 <10.0.19042.1052
Sources
cisa.gov CVE-2021-31955
euvd EUVD-2021-18828

Description

Microsoft Windows Kernel contains an unspecified vulnerability that allows for information disclosure. Successful exploitation allows attackers to read the contents of kernel memory from a user-mode process.

References