CVE-2021-31199

MEDIUM(5.2)KEV

Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability

Description

CVE-2021-31199 is a MEDIUM vulnerability affecting Microsoft Enhanced Cryptographic Provider, carrying a CVSS 3.1 score of 5.2. Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation. This CVE is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of 2021-11-17. With an EPSS score of 0.00981 (76.57th percentile), this vulnerability demonstrates moderate exploitation probability relative to other known vulnerabilities.

KEV Information

Vendor
Microsoft
Product
Enhanced Cryptographic Provider
Date Added
November 3, 2021
Due Date
November 17, 2021
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:NOpen in Calculator
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.0
Impact Score
2.7

Affected Products

VendorProductVersion
microsoftwindows 10 1507< 10.0.10240.18967
microsoftwindows 10 1607< 10.0.14393.4467
microsoftwindows 10 1809< 10.0.17763.1999
microsoftwindows 10 1909< 10.0.18363.1621
microsoftwindows 10 2004< 10.0.19041.1052
microsoftwindows 10 20h2< 10.0.19042.1052
microsoftwindows 10 21h1< 10.0.19043.1052
microsoftwindows 7-
microsoftwindows 8.1-
microsoftwindows rt 8.1-
microsoftwindows server 2004< 10.0.19041.1052
microsoftwindows server 2008-; r2
microsoftwindows server 2012-; r2
microsoftwindows server 2016< 10.0.14393.4467
microsoftwindows server 2019< 10.0.17763.1999
microsoftwindows server 20h2< 10.0.19042.1052

Multiple CVSS Assessments

Source: [email protected](Secondary)
5.2
MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Source: [email protected](Secondary)
7.8
HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

Unspecified Weakness

No specific CWE has been assigned to CVE-2021-31199 by NVD at this time. Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation. The absence of a specific CWE classification does not diminish the severity of this vulnerability. Organizations should focus on applying vendor-recommended patches and monitoring for exploitation indicators regardless of weakness classification.

The vulnerability affects Microsoft Enhanced Cryptographic Provider and has been confirmed as actively exploited in the wild, warranting immediate attention from security teams.

Impact Analysis

CVE-2021-31199 carries a CVSS 3.1 score of 5.2 (MEDIUM) with Changed Scope.

Confidentiality (LOW): Limited information disclosure is possible, potentially exposing some sensitive data within Microsoft Enhanced Cryptographic Provider to unauthorized parties.

Integrity (LOW): Limited modification of data within Microsoft Enhanced Cryptographic Provider is possible, though the scope of alterable data is constrained.

Availability (NONE): No availability impact is expected from exploitation of this vulnerability.

Scope Changed: The vulnerability's scope is Changed (C), meaning exploitation can affect resources beyond the vulnerable component. An attacker exploiting Microsoft Enhanced Cryptographic Provider could potentially impact other systems or components in the environment.

With an EPSS score of 0.00981 (76.57th percentile), this vulnerability shows moderate exploitation probability that should be factored into remediation prioritization.

Exploit Maturity

CVE-2021-31199 has confirmed active exploitation in the wild and is listed in CISA's Known Exploited Vulnerabilities catalog.

Exploit status: This vulnerability has been actively exploited, as confirmed by its inclusion in the KEV catalog. The EPSS score of 0.00981 (76.57th percentile) indicates notable exploitation activity.

Ransomware association: As of the latest KEV data, no direct ransomware association has been confirmed for CVE-2021-31199. However, the confirmed exploitation in the wild means threat actors are actively using this vulnerability in attacks.

Attack surface: The local attack vector means an attacker needs local access or must trick a user into running malicious content on the affected system. No user interaction is required once local access is obtained.

KEV deadline: CISA required federal agencies to remediate this vulnerability by 2021-11-17. All organizations should treat this deadline as a strong recommendation for their own remediation timelines.

Remediation

  1. Apply vendor patches immediately. Apply updates per vendor instructions. Consult the vendor advisory at portal.msrc.microsoft.com for specific patch guidance.
  2. Verify affected product versions in your environment. Identify all instances of Microsoft Enhanced Cryptographic Provider in your infrastructure. Use asset inventory and vulnerability scanning tools to ensure no instances are missed.
  3. Implement interim mitigations if patching is delayed. If immediate patching is not feasible, apply network-level controls such as restricting access to the affected component, enabling enhanced logging, and monitoring for indicators of compromise.
  4. Scan for signs of prior exploitation. Given the confirmed active exploitation of this vulnerability, review system logs and security monitoring data for evidence of compromise. Conduct a thorough investigation if any suspicious activity is detected.
  5. Update detection signatures and monitoring rules. Ensure intrusion detection and prevention systems, endpoint detection tools, and SIEM rules are updated to detect exploitation attempts targeting CVE-2021-31199.
  6. Conduct a post-remediation review. After patching, verify the fix is effective and document the remediation actions taken. Update your vulnerability management records and assess whether any additional hardening measures are warranted.

Technical Details

CVE-2021-31199 is a MEDIUM-severity vulnerability in Microsoft Enhanced Cryptographic Provider that requires local access to the target system for exploitation. The attack complexity is low, meaning no specialized conditions or preparation are required beyond the attack prerequisites. The attacker requires low-level privileges on the target system. No user interaction is required, allowing fully automated exploitation once access is obtained.

Technical mechanism: Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability. While no specific CWE has been assigned, the vulnerability enables privilege escalation through exploitation of an implementation flaw in the affected component.

CVSS 3.1 vector analysis: The vector reflects an Attack Vector of LOCAL, Attack Complexity of LOW, Privileges Required of LOW, User Interaction of NONE, Scope CHANGED, and impact ratings of LOW/LOW/NONE for Confidentiality/Integrity/Availability respectively. The Changed scope means exploitation can impact resources beyond the vulnerable component.

Frequently Asked Questions

Is CVE-2021-31199 being actively exploited?

Yes, CVE-2021-31199 is confirmed to be actively exploited in the wild. It is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, which means federal agencies were required to remediate it by 2021-11-17. While no direct ransomware association has been confirmed, active exploitation is ongoing. The EPSS score of 0.00981 (76.57th percentile) further confirms significant exploitation activity.

Which products are affected by CVE-2021-31199?

This vulnerability affects Microsoft Enhanced Cryptographic Provider. Organizations running affected versions should verify their exposure and prioritize remediation. Check vendor advisories for the complete and most current list of affected versions.

How do I fix CVE-2021-31199?

Apply updates per vendor instructions. Ensure all affected instances of Microsoft Enhanced Cryptographic Provider are identified using vulnerability scanning and asset management tools. If immediate patching is not possible, implement network-level mitigations and enhanced monitoring. After patching, verify the fix and scan for indicators of prior compromise.

How severe is CVE-2021-31199?

CVE-2021-31199 is rated MEDIUM with a CVSS 3.1 score of 5.2. Its EPSS score of 0.00981 places it in the 76.57th percentile for exploitation likelihood. The vulnerability has confirmed active exploitation in the wild and was required to be remediated by federal agencies by 2021-11-17 per CISA's KEV directive.

CVSS Score

5.2
MEDIUM(5.2)

EPSS Score

EPSS Score2.95%
EPSS Percentile86.1%

Dates

PublishedJune 8, 2021
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.