Coverage › CVE-2021-31207
CVE-2021-31207 Mapped Sigma
Microsoft Exchange Server Security Feature Bypass Vulnerability
- Vendor / product
- Microsoft — Exchange Server
- Description (CISA)
- Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.
- Added to KEV
- 2021-11-03
- Due date
- 2021-11-17
- Required action
- Apply updates per vendor instructions.
- Known ransomware use
- Known
- CWE
- CWE-20, CWE-434
- CISA notes
- https://nvd.nist.gov/vuln/detail/CVE-2021-31207
- Elsewhere
- cve.org · NVD · CISA KEV · JSON
ATT&CK techniques · CTID Mappings Explorer, ATT&CK 16.1, KEV snapshot 2025-07-28
2 mapping objects across 2 techniques. exploitation technique states how the vulnerability is exploited; primary and secondary impact state what exploitation achieves. They are different claims and are labelled as such.
| Technique | Mapping type | CTID comment | Status in v19.2 |
|---|---|---|---|
| T1548.002 Bypass User Account Control | exploitation technique | This vulnerability is exploited via authentication bypass, allowing the adversary to write to files. ref 1 · ref 2 |
live |
| T1565 Data Manipulation | primary impact | This vulnerability is exploited via authentication bypass, allowing the adversary to write to files. ref 1 · ref 2 |
live |
Detection chain · ATT&CK Enterprise v19.2 detection strategies, analytics, log sources
T1548.002 Bypass User Account Control exploitation technique
- DET0388 Detection Strategy for T1548.002 – Bypass User Account Control (UAC)
AN1094 WindowsDetects a multi-event behavior chain involving UAC bypass attempts via known auto-elevated binaries (e.g., eventvwr.exe, sdclt.exe), unauthorized Registry changes to UAC-related keys, and anomalous process execution with elevated privileges but lacking standard parent-child lineage. Suspicious patterns include invocation of auto-elevated COM objects or manipulation of isolatedCommand Registry entries without consent prompts.Tunable:
TimeWindowElevatedProcessNameListParentProcessAnomalyThreshold
Sigma rules tagged attack.t1548.002 (56)
Author: Christian Burkard (Nextron Systems)
· 2021-08-23 (modified 2024-12-01) · logsource: product=windows category=process_creation · 0058b9e5-bcd7-40d4-9205-95ca5a16d7b2
Detects the pattern of UAC Bypass using Windows Media Player osksupport.dll (UACMe 32)
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-06-17 · logsource: product=windows category=image_load · 0cbe38c0-270c-41d9-ab79-6e5a9a669290
Detects DLLs loading from a spoofed Windows directory path with an extra space (e.g "C:\Windows \System32") which can bypass Windows trusted path verification.
This technique tricks Windows into treating the path as trusted, allowing malicious DLLs to load with high integrity privileges bypassing UAC.
Author: frack113
· 2024-05-10 · logsource: product=windows category=registry_set · 0d7ceeef-3539-4392-8953-3dc664912714
Detects when an attacker tries to change User Account Control (UAC) elevation request destination via the "PromptOnSecureDesktop" value.
The "PromptOnSecureDesktop" setting specifically determines whether UAC prompts are displayed on the secure desktop. The secure desktop is a separate desktop environment that's isolated from other processes running on the system. It's designed to prevent malicious software from intercepting or tampering with UAC prompts.
When "PromptOnSecureDesktop" is set to 0, UAC prompts are displayed on the user's current desktop instead of the secure desktop. This reduces the level of security because it potentially exposes the prompts to manipulation by malicious software.
Author: Christian Burkard (Nextron Systems)
· 2021-08-30 (modified 2022-01-13) · logsource: product=windows category=registry_event · 152f3630-77c1-4284-bcc0-4cc68ab2f6e7
Detects the shell open key manipulation (exefile and ms-settings) used for persistence and the pattern of UAC Bypass using fodhelper.exe, computerdefaults.exe, slui.exe via registry keys (e.g. UACMe 33 or 62)
Author: Christian Burkard (Nextron Systems)
· 2021-08-30 (modified 2022-10-09) · logsource: product=windows category=file_event · 155dbf56-e0a4-4dd0-8905-8a98705045e8
Detects the pattern of UAC Bypass using a path parsing issue in winsat.exe (UACMe 52)
Author: Christian Burkard (Nextron Systems)
· 2021-08-23 (modified 2024-12-01) · logsource: product=windows category=process_creation · 1ca6bd18-0ba0-44ca-851c-92ed89a61085
Detects the pattern of UAC Bypass using consent.exe and comctl32.dll (UACMe 22)
Author: Teymur Kheirkhabarov (idea), Mangatas Tondang (rule), oscd.community
· 2020-10-13 (modified 2022-10-20) · logsource: product=windows category=process_creation · 1e53dd56-8d83-4eb4-a43e-b790a05510aa
Detects Windows Installer service (msiexec.exe) spawning "cmd" or "powershell"
Author: Ecco
· 2019-08-30 (modified 2023-02-21) · logsource: product=windows category=process_creation · 3268b746-88d8-4cd3-bffc-30077d02c787
Detects some Empire PowerShell UAC bypass methods
Author: Christian Burkard (Nextron Systems)
· 2021-08-30 (modified 2024-12-01) · logsource: product=windows category=process_creation · 39ed3c80-e6a1-431b-9df3-911ac53d08a7
Detects the pattern of UAC Bypass using NTFS reparse point and wusa.exe DLL hijacking (UACMe 36)
Author: Christian Burkard (Nextron Systems)
· 2021-08-31 (modified 2024-12-01) · logsource: product=windows category=process_creation · 3c05e90d-7eba-4324-9972-5d7f711a60a8
Detects tools such as UACMe used to bypass UAC with computerdefaults.exe (UACMe 59)
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)
· 2020-05-02 (modified 2024-12-01) · logsource: product=windows category=process_creation · 40f9af16-589d-4984-b78d-8c2aec023197
A General detection for sdclt being spawned as an elevated process. This could be an indicator of sdclt being used for bypass UAC techniques.
Author: Christian Burkard (Nextron Systems)
· 2021-08-30 (modified 2022-10-09) · logsource: product=windows category=file_event · 41bb431f-56d8-4691-bb56-ed34e390906f
Detects the pattern of UAC Bypass using a msconfig GUI hack (UACMe 55)
Author: frack113
· 2022-01-05 (modified 2023-08-17) · logsource: product=windows category=registry_set · 46dd5308-4572-4d12-aa43-8938f0184d4f
Bypasses User Account Control using a fileless method
Author: frack113
· 2022-01-05 (modified 2024-05-10) · logsource: product=windows category=registry_set · 48437c39-9e5f-47fb-af95-3d663c3f2919
Detects when an attacker tries to disable User Account Control (UAC) by setting the registry value "EnableLUA" to 0.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-07-03 · logsource: product=windows category=file_event · 48ea844d-19b1-4642-944e-fe39c2cc1fec
Detects the creation of a file by "dllhost.exe" in System32 directory part of "IDiagnosticProfileUAC" UAC bypass technique
All 56 rules on the technique page →
T1565 Data Manipulation primary impact
- DET0059 Detection Strategy for Data Manipulation
AN0162 WindowsCorrelate unauthorized or anomalous file modifications, deletions, or metadata changes with suspicious process execution or API calls. Detect abnormal changes to structured data (e.g., database files, logs, financial records) outside expected business process activity.Tunable:
MonitoredFilePathsTimeWindowAuthorizedProcessesAN0163 LinuxDetect unauthorized manipulation of log files, database entries, or system configuration files through auditd and syslog. Correlate shell commands that alter HISTFILE or data-related processes with abnormal file access patterns.auditd:SYSCALLopen, unlink, rename: Suspicious file access, deletion, or modification of sensitive paths→ DC0061 File Modificationlinux:syslogUnexpected SQL or application log entries showing tampered or malformed data→ DC0085 Network Traffic ContentTunable:WatchedDirectoriesCommandExclusionsAN0164 macOSDetect manipulation of system or application files in/Library,/System, or user data directories using FSEvents and Unified Logs. Identify anomalous process execution modifying plist files, structured data, or logs outside expected update cycles.macos:unifiedlogAnomalous plist modifications or sensitive file overwrites by non-standard processes→ DC0061 File Modificationmacos:osqueryopen, execve: Unexpected processes accessing or modifying critical files→ DC0021 OS API ExecutionTunable:AllowedPlistEditorsFileIntegrityBaseline
Sigma rules tagged attack.t1565 (3)
Author: Sittikorn S
· 2021-06-29 (modified 2021-08-20) · logsource: product=aws service=cloudtrail · 16124c2d-e40b-4fcc-8f2c-5ab7870a2223
Identifies disabling of default Amazon Elastic Block Store (EBS) encryption in the current region.
Disabling default encryption does not change the encryption status of your existing volumes.
Author: Austin Songer @austinsonger
· 2021-08-15 (modified 2022-10-09) · logsource: product=gcp service=gcp.audit · 234f9f48-904b-4736-a34c-55d23919e4b7
Identifies when sensitive information is re-identified in google Cloud.
Author: Borna Talebi
· 2021-09-14 (modified 2022-10-09) · logsource: product=windows category=ps_script · 4368354e-1797-463c-bc39-a309effbe8d7
Detects powershell scripts that adds a Name Resolution Policy Table (NRPT) rule for the specified namespace.
This will bypass the default DNS server and uses a specified server for answering the query.