Improper Privilege Management in Microsoft Windows and Windows Server - CVE-2021-31955

 

Improper Privilege Management in Microsoft Windows and Windows Server - CVE-2021-31955

Published: June 8, 2021 / Updated: October 18, 2021


Vulnerability identifier: #VU53890
CSH Severity: Medium
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-31955
CWE-ID: CWE-269
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to improper privilege management. A local unprivileged user can read contents of Kernel memory from a user mode process.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Microsoft Windows
Windows Server
Solutions Enabler Virtual Appliance
Solutions Enabler
Unisphere for PowerMax Virtual Appliance
Unisphere for PowerMax

How to mitigate CVE-2021-31955

Install updates from vendor's website.

Solutions Enabler Virtual Appliance - addressed in versions 9.1.0.17, 9.2.2.0
Solutions Enabler - addressed in versions 9.1.0.17, 9.2.2.0
Unisphere for PowerMax Virtual Appliance - addressed in versions 9.1.0.28, 9.2.2.2
Unisphere for PowerMax - addressed in versions 9.1.0.28, 9.2.2.2

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins