CVE-2021-31956 is a local elevation-of-privilege vulnerability in the Windows NTFS driver, ntfs.sys. Available technical reporting describes it as a heap-based or paged-pool buffer overflow in NTFS extended attribute handling, specifically in the NtfsQueryEaUserEaList code path. The flaw is triggered through NTFS extended attribute operations using system calls such as NtSetEAFile and NtQueryEaFile, where improper handling of buffer length calculations can lead to integer underflow and memory corruption in kernel paged pool memory. Exploitation has been shown to corrupt Windows Notification Facility-related kernel pool objects and derive arbitrary kernel memory read and write primitives. Attackers can then locate process structures, modify thread state, and steal the SYSTEM token to elevate the current process. The vulnerability was used in the wild as part of exploit chains to escape a browser sandbox and obtain full system privileges on supported Windows 10 builds.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This is a small Visual Studio C++ Windows console project consisting of an entry point (Entry.cpp), a method dispatcher and implementation (methods/methods.cpp/.h), and standard solution/project metadata. Method 1 implements the known fodhelper.exe UAC-bypass pattern: it creates the current-user ms-settings shell open command registry key, sets its default value to an operator-supplied executable path, creates an empty DelegateExecute value, and starts fodhelper.exe. It waits briefly and then attempts to delete the hijack artifacts. The default payload is calc.exe, but the executable path is accepted from the command line. If the user is already an administrator, the program bypasses the registry method and directly starts the supplied file using ShellExecuteExA. No network communication, remote endpoint, persistence mechanism, or embedded shellcode is present. Although the README associates the project with CVE-2021-31956 and asserts SYSTEM-level execution, the source specifically implements a local fodhelper registry hijack and does not contain logic to obtain or verify SYSTEM privileges. The project is an operational local privilege-escalation/UAC-bypass proof of concept with a basic customizable command payload.
This repository is a real exploit chain combining a browser RCE with a Windows local privilege escalation. It is not just a PoC snippet: it contains a working browser stage, native shellcode, a standalone Windows EoP binary, build scripts, prebuilt artifacts, and notes documenting an abandoned delivery approach. Structure: the root README explains the full chain and operator workflow. browser-exploit/ contains the Chrome CVE-2020-6418 exploit as a static HTML/JavaScript file plus a Python builder that embeds shellcode into the page. browser-exploit/shellcode/ contains x64 assembly stubs and a C harness for testing shellcode outside the browser. privilege-escalation/ contains a large standalone C exploit for Windows 10 20H1 build 19041.264. notes/ contains earlier unused stubs and a test harness for a failed approach that tried to push the full PE through the V8 arbitrary write primitive. prebuilt/ contains ready-made exploit.html and references to exploit.exe. Main capability: exploit_template.html abuses CVE-2020-6418 in V8 Turbofan to corrupt a Float64Array length, build relative and absolute read/write primitives, locate a WebAssembly RWX page, and overwrite it with native shellcode. The shellcode is not a full payload; it is a downloader/launcher stub. That stub manually resolves Windows APIs by walking the PEB and PE export tables, loads urlmon.dll, calls URLDownloadToFileA to fetch a second-stage executable from an attacker-controlled HTTP server, saves it to disk, and launches it with WinExec. Second stage: privilege-escalation/exploit.c is a standalone local privilege escalation tool targeting Windows 10 20H1 build 19041.264 x64. According to the code and documentation, it first recovers the kernel base using a PREFETCH+RDTSCP timing side channel, then abuses a missing length check in NtPowerInformation BootStat integrity handling to gain a write-{0,1} primitive against an arbitrary kernel address, specifically to disable ExIsRestrictedCaller protections by modifying SepMediumDaclSd-related state. It then uses CVE-2021-31956 in ntfs.sys Extended Attribute handling to establish a stable arbitrary kernel read/write primitive via named pipe attributes. With that primitive, it locates SYSTEM’s token and copies it into the current process, then spawns a SYSTEM shell and attempts cleanup/repair of kernel state. Operational notes: the exploit is highly version-specific and depends on hardcoded offsets in both the browser and kernel stages. It requires Chrome 80.0.3987.87 x64, Windows 10 19041.264 x64, and Chrome launched with --no-sandbox. The default second-stage URL is hardcoded as http://192.168.37.1:8000/exploit.exe, and the default drop path is C:\lab8\exploit.exe. The repository’s prebuilt exploit.html embeds that same network configuration. Overall maturity is OPERATIONAL: the payload is functional and complete, but configuration is largely hardcoded rather than framework-driven.
This repository is a Proof-of-Concept (PoC) exploit for CVE-2021-31956, a Windows kernel (NTFS) local privilege escalation vulnerability. The code is written in C++ and structured as a Visual Studio project. The main exploit logic resides in '31956Custom/Main.cpp', which orchestrates the attack by: - Initializing access to undocumented NT* API functions from ntdll.dll. - Leaking the EPROCESS address of the current process using a technique related to CVE-2021-31955 (Superfetch/SysInfo leak). - Crafting a file ('TriggerBug') with specific NTFS extended attributes to trigger a heap overflow in the kernel. - Corrupting WNF (Windows Notification Facility) state data structures in kernel memory to gain arbitrary read/write capabilities. - Stealing the SYSTEM token from the SYSTEM process and assigning it to the current process, then spawning a SYSTEM shell (cmd.exe). The exploit is highly dependent on hardcoded kernel structure offsets, which may need adjustment for different Windows builds. The README notes that the exploit is a work-in-progress and may destabilize the system (potential for BSOD or instability after use). The code does not target remote or network endpoints; it is strictly a local privilege escalation exploit. The repository includes references to related research and prior PoCs for both CVE-2021-31956 and CVE-2021-31955.
This repository contains a local privilege escalation exploit for CVE-2021-31956, targeting Microsoft Windows 10 20H2. The main exploit logic is implemented in 'CVE-2021-31956.c', with supporting structures and definitions in 'CVE-2021-31956.h'. The exploit leverages a heap overflow in the Windows Notification Facility (WNF) to manipulate kernel memory and ultimately steal the SYSTEM process token, granting the attacker SYSTEM privileges. The exploit is operational and requires local execution on a vulnerable Windows system. The README notes that the user must specify a writable directory for file operations, and that the exploit will create a new console window. The repository includes Visual Studio project files for building the exploit. No network endpoints are involved; the attack vector is purely local. The exploit is not part of a framework and is a standalone proof-of-concept with a working privilege escalation payload.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows kernel paged pool buffer overflow vulnerability used for sandbox escape and privilege escalation to SYSTEM as part of Magnitude's Chromium exploit chain.
A local privilege escalation vulnerability in the Windows kernel (NTFS Paged Pool Memory corruption).
A heap-based buffer overflow vulnerability in Windows ntfs.sys that can be exploited for elevation of privilege by creating arbitrary kernel memory read/write primitives.
A Windows NTFS elevation-of-privilege zero-day used in the wild as part of an exploit chain to escape the sandbox and gain system privileges on modern Windows 10 systems.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.