CVE-2021-38624
published 2021-09-15CVE-2021-38624: Windows Key Storage Provider Security Feature Bypass Vulnerability
PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
1.52%
72.8th percentile
Windows Key Storage Provider Security Feature Bypass Vulnerability
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.2237 | 10.0.17763.2237 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.2237 | 10.0.17763.2237 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.1854 | 10.0.18363.1854 |
| microsoft | windows_10_version_2004 | >= 10.0.0 < 10.0.19041.1288 | 10.0.19041.1288 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1288 | 10.0.19042.1288 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1288 | 10.0.19043.1288 |
| microsoft | windows_11_version_21h2 | >= 10.0.22000.0 < 10.0.22000.258 | 10.0.22000.258 |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.2237 | 10.0.17763.2237 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.288 | 10.0.20348.288 |
| microsoft | windows_server_version_2004 | >= 10.0.0 < 10.0.19041.1288 | 10.0.19041.1288 |
| microsoft | windows_server_version_20h2 | >= 10.0.0 < 10.0.19042.1288 | 10.0.19042.1288 |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_1909 | — | — |
| msrc | windows_10_version_2004 | — | — |
| msrc | windows_10_version_20h2 | — | — |
| msrc | windows_10_version_21h1 | — | — |
| msrc | windows_11_version_21h2 | — | — |
| msrc | windows_server_2019 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_msrc6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Windows up to Server 2022 Key Storage Provider authorization
vuldb·2026-08-13·CVSS 6.5
CVE-2021-38624 [MEDIUM] Microsoft Windows up to Server 2022 Key Storage Provider authorization
A vulnerability classified as problematic was found in Microsoft Windows. Affected by this vulnerability is an unknown functionality of the component Key Storage Provider. Executing a manipulation can lead to authorization bypass.
The identification of this vulnerability is CVE-2021-38624. The attack may be launched remotely. There is no exploit available.
It is advisable to implement a patch to correct this issue.
GHSA
GHSA-47qf-6fqv-2m82: Windows Key Storage Provider Security Feature Bypass Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-38624 [MEDIUM] CWE-639 GHSA-47qf-6fqv-2m82: Windows Key Storage Provider Security Feature Bypass Vulnerability
Windows Key Storage Provider Security Feature Bypass Vulnerability
Microsoft
Windows Key Storage Provider Security Feature Bypass Vulnerability
vendor_msrc·2021-09-14·CVSS 6.5
CVE-2021-38624 [MEDIUM] Windows Key Storage Provider Security Feature Bypass Vulnerability
Windows Key Storage Provider Security Feature Bypass Vulnerability
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
A successful attacker could bypass the Windows Key Storage Provider which issues key certificates for trust in attestation scenarios.
Windows Key Storage Provider: Windows Key Storage Provider
Microsoft: Microsoft
Impact: Security Feature Bypass
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5006672
Reference: https://support.microsoft.com/help/5006672
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5006667
Referenc
No detection rules found.
No public exploits indexed.
2021-09-15
Published