Executive brief
Microsoft Enhanced Cryptographic Provider contains an elevation of privilege vulnerability that allows a local attacker to gain elevated permissions. The vulnerability has been observed being exploited in the wild and is tracked in CISA's Known Exploited Vulnerabilities catalog.
Affected products
- Microsoft Windows 10 1507, 1607, 1809, 1909, 2004, 20H2, 21H1
- Microsoft Windows Server 2008, 2008 R2, 2012, 2012 R2, 2016, 2019, 2004, 20H2
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1 -
- Microsoft Windows RT 8.1 -
Timeline
- 2021-06-08: disclosed: NVD Published Date
- 2021-11-03: kev added: Date added to CISA KEV catalog
- 2021-11-03: exploited: Reported exploited in the wild