ZeroHour

CVE-2021-31201

KEVmass2

Local Privilege Escalation in Microsoft Enhanced Cryptographic Provider (Windows)

CISA: Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability

CVSS 3.1
5.2 medium
EPSS
3%p85
Published
()
KEV added
AI analysis

CVE-2021-31201 is an elevation-of-privilege flaw in the Microsoft Enhanced Cryptographic Provider, a core Windows cryptographic component shipped with a wide range of Windows client and server releases. A local attacker who already runs code with low privileges on an affected system can abuse the provider to gain elevated privileges without user interaction (CVSS:3.1 AV:L/PR:L/UI:N, scope changed). Because the component is present by default, affected Windows 7 through Windows 10 21H1 and Windows Server 2008/2004-era installations are exposed until patched. Microsoft fixed the bug in the June 2021 Patch Tuesday release as one of six zero-days known to be actively exploited, with attacks attributed to the Austrian firm DSIRF deploying the Subzero surveillance malware. CISA added the issue to its Known Exploited Vulnerabilities catalog on 2021-11-03, directing agencies to apply vendor updates; no public proof-of-concept is known, but real-world exploitation is confirmed.

What to do: Apply the June 2021 Patch Tuesday Windows security updates (or any later cumulative update) on all affected Windows 7/8.1/RT 8.1, Windows 10 (1507-21H1), and Windows Server 2008/2004 systems per Microsoft's instructions, and verify installation through your patch inventory. Prioritize endpoints of high-value users and internet-exposed servers, since exploitation was confirmed in the wild and this CVE is on the CISA KEV list. No standalone workaround was documented in the source data; patching is the required action.

Affected
microsoft Windows 101507, 1607, 1809, 1909, 2004, 20H2, 21H1
microsoft Windows 7
microsoft Windows 8.1
microsoft Windows RT 8.1
microsoft Windows Server 2008
microsoft Windows Server 2004 (Windows Server, version 2004)
Microsoft Enhanced Cryptographic Provider (affected component)shipped with the Windows releases listed above
Estimated exposure
masshundreds of millions of Windows endpoints (essentially the entire supported Windows client and server install base in mid-2021) — The affected branches (Windows 7, 8.1, RT 8.1, Windows 10 1507-21H1, Server 2008/2004) covered virtually all supported Windows deployments at the time of disclosure per public OS market-share data, and the vulnerable cryptographic provider…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Enhanced Cryptographic Provider
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 1909, windows 10 2004, windows 10 20h2, windows 10 21h1, windows 7, windows 8.1, windows rt 8.1, windows server 2004, windows server 2008
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

In the news