Junglewise Threat Intelligence

CVE-2021-31199: Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability

CVE-2021-31199 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Windows 8.1, Microsoft Windows Server, Microsoft Windows 7, Microsoft Windows 10, Microsoft Windows Rt 8.1. Vendors: Microsoft.

Executive brief

Microsoft Enhanced Cryptographic Provider contains an elevation of privilege vulnerability that allows a local attacker to gain elevated permissions on a target system. The vulnerability has been observed being exploited in the wild and is tracked in CISA's Known Exploited Vulnerabilities catalog.

Affected products

  • Microsoft Windows 10 1507, 1607, 1809, 1909, 2004, 20H2, 21H1
  • Microsoft Windows Server 2008, 2008 R2, 2012, 2012 R2, 2016, 2019, 2004, 20H2
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8.1 -
  • Microsoft Windows RT 8.1 -

Timeline

  • 2021-06-08: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-17: other: CISA due date for remediation

Related threats