CVE-2021-31956 is a heap-based buffer overflow in the Windows NTFS kernel driver's NtfsQueryEaUserEaList function. Improper handling of integer underflow during extended-attribute output-buffer length checks permits corruption of paged-pool memory. Exploits combine this corruption with Windows Notification Facility objects to obtain arbitrary kernel-memory read and write capabilities and elevate a process to SYSTEM privileges. The vulnerability was exploited as a zero-day in PuzzleMaker attacks and subsequently incorporated into the Magnitude exploit kit.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This is a small Visual Studio C++ Windows console project consisting of an entry point (Entry.cpp), a method dispatcher and implementation (methods/methods.cpp/.h), and standard solution/project metadata. Method 1 implements the known fodhelper.exe UAC-bypass pattern: it creates the current-user ms-settings shell open command registry key, sets its default value to an operator-supplied executable path, creates an empty DelegateExecute value, and starts fodhelper.exe. It waits briefly and then attempts to delete the hijack artifacts. The default payload is calc.exe, but the executable path is accepted from the command line. If the user is already an administrator, the program bypasses the registry method and directly starts the supplied file using ShellExecuteExA. No network communication, remote endpoint, persistence mechanism, or embedded shellcode is present. Although the README associates the project with CVE-2021-31956 and asserts SYSTEM-level execution, the source specifically implements a local fodhelper registry hijack and does not contain logic to obtain or verify SYSTEM privileges. The project is an operational local privilege-escalation/UAC-bypass proof of concept with a basic customizable command payload.
This repository is a real exploit chain combining a browser RCE with a Windows local privilege escalation. It is not just a PoC snippet: it contains a working browser stage, native shellcode, a standalone Windows EoP binary, build scripts, prebuilt artifacts, and notes documenting an abandoned delivery approach. Structure: the root README explains the full chain and operator workflow. browser-exploit/ contains the Chrome CVE-2020-6418 exploit as a static HTML/JavaScript file plus a Python builder that embeds shellcode into the page. browser-exploit/shellcode/ contains x64 assembly stubs and a C harness for testing shellcode outside the browser. privilege-escalation/ contains a large standalone C exploit for Windows 10 20H1 build 19041.264. notes/ contains earlier unused stubs and a test harness for a failed approach that tried to push the full PE through the V8 arbitrary write primitive. prebuilt/ contains ready-made exploit.html and references to exploit.exe. Main capability: exploit_template.html abuses CVE-2020-6418 in V8 Turbofan to corrupt a Float64Array length, build relative and absolute read/write primitives, locate a WebAssembly RWX page, and overwrite it with native shellcode. The shellcode is not a full payload; it is a downloader/launcher stub. That stub manually resolves Windows APIs by walking the PEB and PE export tables, loads urlmon.dll, calls URLDownloadToFileA to fetch a second-stage executable from an attacker-controlled HTTP server, saves it to disk, and launches it with WinExec. Second stage: privilege-escalation/exploit.c is a standalone local privilege escalation tool targeting Windows 10 20H1 build 19041.264 x64. According to the code and documentation, it first recovers the kernel base using a PREFETCH+RDTSCP timing side channel, then abuses a missing length check in NtPowerInformation BootStat integrity handling to gain a write-{0,1} primitive against an arbitrary kernel address, specifically to disable ExIsRestrictedCaller protections by modifying SepMediumDaclSd-related state. It then uses CVE-2021-31956 in ntfs.sys Extended Attribute handling to establish a stable arbitrary kernel read/write primitive via named pipe attributes. With that primitive, it locates SYSTEM’s token and copies it into the current process, then spawns a SYSTEM shell and attempts cleanup/repair of kernel state. Operational notes: the exploit is highly version-specific and depends on hardcoded offsets in both the browser and kernel stages. It requires Chrome 80.0.3987.87 x64, Windows 10 19041.264 x64, and Chrome launched with --no-sandbox. The default second-stage URL is hardcoded as http://192.168.37.1:8000/exploit.exe, and the default drop path is C:\lab8\exploit.exe. The repository’s prebuilt exploit.html embeds that same network configuration. Overall maturity is OPERATIONAL: the payload is functional and complete, but configuration is largely hardcoded rather than framework-driven.
This repository is a Proof-of-Concept (PoC) exploit for CVE-2021-31956, a Windows kernel (NTFS) local privilege escalation vulnerability. The code is written in C++ and structured as a Visual Studio project. The main exploit logic resides in '31956Custom/Main.cpp', which orchestrates the attack by: - Initializing access to undocumented NT* API functions from ntdll.dll. - Leaking the EPROCESS address of the current process using a technique related to CVE-2021-31955 (Superfetch/SysInfo leak). - Crafting a file ('TriggerBug') with specific NTFS extended attributes to trigger a heap overflow in the kernel. - Corrupting WNF (Windows Notification Facility) state data structures in kernel memory to gain arbitrary read/write capabilities. - Stealing the SYSTEM token from the SYSTEM process and assigning it to the current process, then spawning a SYSTEM shell (cmd.exe). The exploit is highly dependent on hardcoded kernel structure offsets, which may need adjustment for different Windows builds. The README notes that the exploit is a work-in-progress and may destabilize the system (potential for BSOD or instability after use). The code does not target remote or network endpoints; it is strictly a local privilege escalation exploit. The repository includes references to related research and prior PoCs for both CVE-2021-31956 and CVE-2021-31955.
This repository contains a local privilege escalation exploit for CVE-2021-31956, targeting Microsoft Windows 10 20H2. The main exploit logic is implemented in 'CVE-2021-31956.c', with supporting structures and definitions in 'CVE-2021-31956.h'. The exploit leverages a heap overflow in the Windows Notification Facility (WNF) to manipulate kernel memory and ultimately steal the SYSTEM process token, granting the attacker SYSTEM privileges. The exploit is operational and requires local execution on a vulnerable Windows system. The README notes that the user must specify a writable directory for file operations, and that the exploit will create a new console window. The repository includes Visual Studio project files for building the exploit. No network endpoints are involved; the attack vector is purely local. The exploit is not part of a framework and is a standalone proof-of-concept with a working privilege escalation payload.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only through a reference to Windows kernel NTFS exploitation research; the supplied article does not analyze this vulnerability.
A Windows kernel NTFS vulnerability mentioned only through the title of a cited exploitation reference. The content does not analyze its underlying flaw or connect it to the CLFS vulnerability.
A Windows kernel paged pool buffer overflow vulnerability used for sandbox escape and privilege escalation to SYSTEM as part of Magnitude's Chromium exploit chain.
A local privilege escalation vulnerability in the Windows kernel (NTFS Paged Pool Memory corruption).
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.