LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-31199: Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-31199 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation.

CVE-2021-31199 is a privilege escalation vulnerability in the Microsoft Enhanced Cryptographic Provider. An attacker who can already run code in a less-privileged context may be able to gain higher privileges on the system. Privilege escalation flaws matter because they turn limited footholds into full control, enabling further lateral movement, persistence, or data access. Specifics of affected builds and exact conditions must be confirmed against the Microsoft vendor advisory.

CISA notes that the component contains an unspecified vulnerability allowing privilege escalation and directs organizations to apply updates per vendor instructions. Known ransomware use is not documented for this CVE.

How it works

The weakness sits in the Microsoft Enhanced Cryptographic Provider, a Windows cryptographic component used for cryptographic operations. The CWE is not specified in the available record; CISA describes only an unspecified vulnerability that permits privilege escalation.

In general terms for this class of issue, an attacker who has already obtained the ability to execute code or interact with the provider under a lower-privileged account abuses the flaw to elevate to a higher integrity level or administrative context. Exact trigger conditions, required local access, and exploitation mechanics are not detailed in the provided facts and must be taken from the vendor advisory rather than assumed. Defenders should treat it as a local elevation path that amplifies the impact of any prior compromise.

Am I affected? How to find it in your systems

The Microsoft Enhanced Cryptographic Provider is part of the Windows cryptographic stack and is typically present on Windows clients and servers that use the platform’s crypto APIs. It is not a separately installed third-party product; exposure depends on the Windows build and update level.

If your environment includes hardened or air-gapped Windows images, verify those images as well, because the component is part of the base OS.

How to remediate

Patch first. Apply the security updates Microsoft released for CVE-2021-31199 exactly as directed in the vendor advisory and per CISA’s required action to “Apply updates per vendor instructions.”

If you can't patch immediately

Compensating controls reduce but do not eliminate risk until the vendor update is applied.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities are commonly used after an initial foothold to deepen access and can lead to data theft or ransomware staging, even though ransomware use is not documented for this specific CVE. If you have reason to believe systems were compromised before patching, follow your incident-response process: isolate affected hosts, preserve evidence, rotate credentials, and assess what data the elevated context could have reached. As one additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether associated credentials or personal information have appeared in prior breaches.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Enhanced Cryptographic Provider
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities