logo

Windows NTFS Kernel Exploit with WNF (Part 1)

ID: c9c4f3c8-61a8-51f5-9f80-e6ed6e54cfe5

STIX ID: report--c9c4f3c8-61a8-51f5-9f80-e6ed6e54cfe5

Feed Name: NCC Research

Threat Score
75/100

Date Published: 2026-05-13

Date Updated: 2026-07-31

...
...

This blog post analyzes CVE-2021-31956, a Windows NTFS local privilege-escalation vulnerability patched in June 2021, showing how crafted NTFS extended attributes trigger an underflow that copies attacker-controlled data out-of-bounds. The author details exploitation constraints, kernel paged-pool layout, and how the Windows Notification Facility (WNF) can be abused to obtain controlled paged-pool allocations, frees, relative reads/writes, and demonstrates steps toward corrupting EPROCESS structures and achieving privilege escalation, while discussing mitigations and future reliability work.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.