← back
CVE-2021-31199

Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

CVSS 5.2 MEDIUMEPSS 3.0%● KEV
In short

A flaw in Microsoft's Enhanced Cryptographic Provider allows an attacker with local access to gain higher privileges on the system. An attacker could exploit this vulnerability to run code with administrative rights without proper authorization.

Technical detail

Local privilege escalation vulnerability in Microsoft Enhanced Cryptographic Provider requiring local user access. The vulnerability allows an authenticated attacker to elevate privileges to system or administrator level through improper access control mechanisms in the cryptographic provider module.

Summary generated and translated by AI from the official description.
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N/E:F/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →