ZeroHour

CVE-2021-31199

KEVmass

Elevation of Privilege in Microsoft Enhanced Cryptographic Provider (Windows)

CISA: Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability

CVSS 3.1
5.2 medium
EPSS
3%p86
Published
()
KEV added
AI analysis

CVE-2021-31199 is an elevation-of-privilege vulnerability in the Microsoft Enhanced Cryptographic Provider, a core Windows component that provides cryptographic services to applications. It carries a CVSS 3.1 score of 5.2 (AV:L/AC:L/PR:L/UI:N/S:C), meaning it is triggered by an attacker who already runs low-privileged code locally on a vulnerable Windows system, with no user interaction required, and lets the attacker break out of the intended security scope to gain elevated privileges. The gain is higher privileges on the compromised host, typically used as a stepping stone in a broader intrusion or malware delivery chain. Exposure is broad: any unpatched Windows 7, 8.1, RT 8.1, Windows 10 (versions 1507 through 21H1), Windows Server 2008, or Windows Server 2004 system is affected, since the provider ships with Windows itself. Exploitation is confirmed in the wild: it was one of the actively exploited Windows zero-days fixed in Microsoft's mid-2021 Patch Tuesday release (part of the six/seven-zero-day coverage), Microsoft attributed targeted attacks to the Austrian firm DSIRF using its Subzero surveillance malware, and the flaw was added to CISA's KEV on 2021-11-03; EPSS estimates a 3.0% chance of exploitation in the next 30 days (86th percentile) and no public PoC is known.

What to do: Apply Microsoft's security updates (the monthly Patch Tuesday cumulative updates covering this CVE) per vendor instructions for every in-scope Windows version — the flaw is in CISA KEV, so patching is mandatory for federal agencies and there is no documented workaround. Verify hosts have received the updated cumulative update, prioritizing multi-user endpoints, RDP/terminal servers, and workstations where untrusted code runs; if patching is delayed, hunt for signs of targeted intrusion consistent with DSIRF/Subzero activity.

Affected
microsoft Windows 101507, 1607, 1809, 1909, 2004, 20H2, 21H1
microsoft Windows 7all supported builds at time of disclosure
microsoft Windows 8.1all supported builds
microsoft Windows RT 8.1RT 8.1
microsoft Windows Server 2008all supported editions/builds listed by Microsoft
microsoft Windows Server 2004version 2004
Estimated exposure
mass≈1 billion+ Windows devices (Windows 10 alone had over 1 billion active devices, and the affected set also includes Windows 7/8.1/RT 8.1 and Windows Server… — The Microsoft Enhanced Cryptographic Provider is a built-in Windows component present on every affected OS installation, so exposure scales with the installed base of Windows 10 (reported by Microsoft at 1+ billion devices) plus the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Enhanced Cryptographic Provider
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 1909, windows 10 2004, windows 10 20h2, windows 10 21h1, windows 7, windows 8.1, windows rt 8.1, windows server 2004, windows server 2008
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

In the news