CVE-2021-31201
KEVmass2Local Privilege Escalation in Microsoft Enhanced Cryptographic Provider (Windows)
CISA: Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability
CVE-2021-31201 is an elevation-of-privilege flaw in the Microsoft Enhanced Cryptographic Provider, a core Windows cryptographic component shipped with a wide range of Windows client and server releases. A local attacker who already runs code with low privileges on an affected system can abuse the provider to gain elevated privileges without user interaction (CVSS:3.1 AV:L/PR:L/UI:N, scope changed). Because the component is present by default, affected Windows 7 through Windows 10 21H1 and Windows Server 2008/2004-era installations are exposed until patched. Microsoft fixed the bug in the June 2021 Patch Tuesday release as one of six zero-days known to be actively exploited, with attacks attributed to the Austrian firm DSIRF deploying the Subzero surveillance malware. CISA added the issue to its Known Exploited Vulnerabilities catalog on 2021-11-03, directing agencies to apply vendor updates; no public proof-of-concept is known, but real-world exploitation is confirmed.
What to do: Apply the June 2021 Patch Tuesday Windows security updates (or any later cumulative update) on all affected Windows 7/8.1/RT 8.1, Windows 10 (1507-21H1), and Windows Server 2008/2004 systems per Microsoft's instructions, and verify installation through your patch inventory. Prioritize endpoints of high-value users and internet-exposed servers, since exploitation was confirmed in the wild and this CVE is on the CISA KEV list. No standalone workaround was documented in the source data; patching is the required action.
| microsoft Windows 10 | 1507, 1607, 1809, 1909, 2004, 20H2, 21H1 |
| microsoft Windows 7 | — |
| microsoft Windows 8.1 | — |
| microsoft Windows RT 8.1 | — |
| microsoft Windows Server 2008 | — |
| microsoft Windows Server 2004 (Windows Server, version 2004) | — |
| Microsoft Enhanced Cryptographic Provider (affected component) | shipped with the Windows releases listed above |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
- Affected
- Microsoft Enhanced Cryptographic Provider
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 1909, windows 10 2004, windows 10 20h2, windows 10 21h1, windows 7, windows 8.1, windows rt 8.1, windows server 2004, windows server 2008
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N