CVE-2021-31199

MEDIUM(5.2)KEV

Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability

Description

Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

KEV Information

Vendor
Microsoft
Product
Enhanced Cryptographic Provider
Date Added
November 3, 2021
Due Date
November 17, 2021
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:NOpen in Calculator
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.0
Impact Score
2.7

Affected Products

VendorProductVersion
microsoftwindows 10 1507< 10.0.10240.18967
microsoftwindows 10 1607< 10.0.14393.4467
microsoftwindows 10 1809< 10.0.17763.1999
microsoftwindows 10 1909< 10.0.18363.1621
microsoftwindows 10 2004< 10.0.19041.1052
microsoftwindows 10 20h2< 10.0.19042.1052
microsoftwindows 10 21h1< 10.0.19043.1052
microsoftwindows 7-
microsoftwindows 8.1-
microsoftwindows rt 8.1-
microsoftwindows server 2004< 10.0.19041.1052
microsoftwindows server 2008-; r2
microsoftwindows server 2012-; r2
microsoftwindows server 2016< 10.0.14393.4467
microsoftwindows server 2019< 10.0.17763.1999
microsoftwindows server 20h2< 10.0.19042.1052

Multiple CVSS Assessments

Source: [email protected](Secondary)
5.2
MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Source: [email protected](Secondary)
7.8
HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

CVSS Score

5.2
MEDIUM(5.2)

EPSS Score

EPSS Score2.95%
EPSS Percentile85.7%

Dates

PublishedJune 8, 2021
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.