CVE detail
CVE-2021-31979
Windows Kernel Elevation of Privilege Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 16.1 · diversity 8.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
4 source links · newest first
Experts said that Israeli surveillance firm Candiru, tracked as Sourgum, exploited zero-days to deliver a new Windows spyware. Microsoft and Citizen Lab believe that the secretive Israel-based Israeli surveillance firm Candiru, tracked as Sourgum, used Windows zero-day exploits to deliver a new Windows spyware dubbed DevilsTongue. According to the experts, at least 100 activists, journalists […]
newssecurityaffairs.comJul 15, 2021, 9:23 PMA secretive Israeli commercial surveillance company named after a parasitic freshwater fish is being blamed for supplying Windows and Chrome zero-day exploits to nation-state APT actors.
newswww.securityweek.comJul 15, 2021, 8:30 PM- July 2021 Patch Tuesday: Microsoft fixes 4 actively exploited bugsHelp Net Security
On this July 2021 Patch Tuesday: Microsoft has fixed 117 CVEs, 4 of which are actively exploited Adobe has delivered security updates for Acrobat and Reader, Bridge, Framemaker, Illustrator, and Dimension VMware has fixed two vulnerabilities in VMware ESXi and VMware Cloud Foundation SAP has released 12 security notes and updated 3 Intel has fixed an EOP bug affecting some of its Xeon and Core X-series processors Mozilla has upgraded Firefox and Firefox ESR, fixed … More →
newswww.helpnetsecurity.comJul 13, 2021, 7:16 PM Microsoft’s Patch Tuesday bundle for July 2021 landed with a loud thud as the world’s largest software maker warns of a new wave of zero-day attacks hitting its flagship Windows operating system.
newswww.securityweek.comJul 13, 2021, 5:52 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2021-43226CVSS 7.8 · High
Windows Common Log File System Driver Elevation of Privilege Vulnerability
KEV listed3 mentions - CVE-2021-41379CVSS 5.5 · Medium
Windows Installer Elevation of Privilege Vulnerability
- CVE-2021-40449CVSS 7.8 · High
Win32k Elevation of Privilege Vulnerability
- CVE-2021-40444CVSS 8.8 · High
<p>Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exp…
- CVE-2021-36955CVSS 7.8 · High
Windows Common Log File System Driver Elevation of Privilege Vulnerability
KEV listed1 mention - CVE-2021-34484CVSS 7.8 · High
Windows User Profile Service Elevation of Privilege Vulnerability
KEV listed4 mentions