kevmap

Coverage › CVE-2021-31207

CVE-2021-31207 Mapped Sigma

Microsoft Exchange Server Security Feature Bypass Vulnerability

Vendor / product
Microsoft — Exchange Server
Description (CISA)
Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.
Added to KEV
2021-11-03
Due date
2021-11-17
Required action
Apply updates per vendor instructions.
Known ransomware use
Known
CWE
CWE-20, CWE-434
CISA notes
https://nvd.nist.gov/vuln/detail/CVE-2021-31207
Elsewhere
cve.org · NVD · CISA KEV · JSON

ATT&CK techniques · CTID Mappings Explorer, ATT&CK 16.1, KEV snapshot 2025-07-28

2 mapping objects across 2 techniques. exploitation technique states how the vulnerability is exploited; primary and secondary impact state what exploitation achieves. They are different claims and are labelled as such.

TechniqueMapping typeCTID commentStatus in v19.2
T1548.002 Bypass User Account Control exploitation technique This vulnerability is exploited via authentication bypass, allowing the adversary to write to files.
ref 1 · ref 2
live
T1565 Data Manipulation primary impact This vulnerability is exploited via authentication bypass, allowing the adversary to write to files.
ref 1 · ref 2
live

Detection chain · ATT&CK Enterprise v19.2 detection strategies, analytics, log sources

T1548.002 Bypass User Account Control exploitation technique

Sigma rules tagged attack.t1548.002 (56)

Author: Christian Burkard (Nextron Systems) · 2021-08-23 (modified 2024-12-01) · logsource: product=windows category=process_creation · 0058b9e5-bcd7-40d4-9205-95ca5a16d7b2
Detects the pattern of UAC Bypass using Windows Media Player osksupport.dll (UACMe 32)
Techniques: T1548.002
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-06-17 · logsource: product=windows category=image_load · 0cbe38c0-270c-41d9-ab79-6e5a9a669290
Detects DLLs loading from a spoofed Windows directory path with an extra space (e.g "C:\Windows \System32") which can bypass Windows trusted path verification. This technique tricks Windows into treating the path as trusted, allowing malicious DLLs to load with high integrity privileges bypassing UAC.
Techniques: T1574.007T1548.002
Author: frack113 · 2024-05-10 · logsource: product=windows category=registry_set · 0d7ceeef-3539-4392-8953-3dc664912714
Detects when an attacker tries to change User Account Control (UAC) elevation request destination via the "PromptOnSecureDesktop" value. The "PromptOnSecureDesktop" setting specifically determines whether UAC prompts are displayed on the secure desktop. The secure desktop is a separate desktop environment that's isolated from other processes running on the system. It's designed to prevent malicious software from intercepting or tampering with UAC prompts. When "PromptOnSecureDesktop" is set to 0, UAC prompts are displayed on the user's current desktop instead of the secure desktop. This reduces the level of security because it potentially exposes the prompts to manipulation by malicious software.
Techniques: T1548.002
Author: Christian Burkard (Nextron Systems) · 2021-08-30 (modified 2022-01-13) · logsource: product=windows category=registry_event · 152f3630-77c1-4284-bcc0-4cc68ab2f6e7
Detects the shell open key manipulation (exefile and ms-settings) used for persistence and the pattern of UAC Bypass using fodhelper.exe, computerdefaults.exe, slui.exe via registry keys (e.g. UACMe 33 or 62)
Techniques: T1548.002T1546.001
Author: Christian Burkard (Nextron Systems) · 2021-08-30 (modified 2022-10-09) · logsource: product=windows category=file_event · 155dbf56-e0a4-4dd0-8905-8a98705045e8
Detects the pattern of UAC Bypass using a path parsing issue in winsat.exe (UACMe 52)
Techniques: T1548.002
Author: Christian Burkard (Nextron Systems) · 2021-08-23 (modified 2024-12-01) · logsource: product=windows category=process_creation · 1ca6bd18-0ba0-44ca-851c-92ed89a61085
Detects the pattern of UAC Bypass using consent.exe and comctl32.dll (UACMe 22)
Techniques: T1548.002
Author: Teymur Kheirkhabarov (idea), Mangatas Tondang (rule), oscd.community · 2020-10-13 (modified 2022-10-20) · logsource: product=windows category=process_creation · 1e53dd56-8d83-4eb4-a43e-b790a05510aa
Detects Windows Installer service (msiexec.exe) spawning "cmd" or "powershell"
Techniques: T1548.002
Author: Ecco · 2019-08-30 (modified 2023-02-21) · logsource: product=windows category=process_creation · 3268b746-88d8-4cd3-bffc-30077d02c787
Detects some Empire PowerShell UAC bypass methods
Techniques: T1548.002
Author: Christian Burkard (Nextron Systems) · 2021-08-30 (modified 2024-12-01) · logsource: product=windows category=process_creation · 39ed3c80-e6a1-431b-9df3-911ac53d08a7
Detects the pattern of UAC Bypass using NTFS reparse point and wusa.exe DLL hijacking (UACMe 36)
Techniques: T1548.002
Author: Christian Burkard (Nextron Systems) · 2021-08-31 (modified 2024-12-01) · logsource: product=windows category=process_creation · 3c05e90d-7eba-4324-9972-5d7f711a60a8
Detects tools such as UACMe used to bypass UAC with computerdefaults.exe (UACMe 59)
Techniques: T1548.002
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research) · 2020-05-02 (modified 2024-12-01) · logsource: product=windows category=process_creation · 40f9af16-589d-4984-b78d-8c2aec023197
A General detection for sdclt being spawned as an elevated process. This could be an indicator of sdclt being used for bypass UAC techniques.
Techniques: T1548.002
Author: Christian Burkard (Nextron Systems) · 2021-08-30 (modified 2022-10-09) · logsource: product=windows category=file_event · 41bb431f-56d8-4691-bb56-ed34e390906f
Detects the pattern of UAC Bypass using a msconfig GUI hack (UACMe 55)
Techniques: T1548.002
Author: frack113 · 2022-01-05 (modified 2023-08-17) · logsource: product=windows category=registry_set · 46dd5308-4572-4d12-aa43-8938f0184d4f
Bypasses User Account Control using a fileless method
Techniques: T1548.002
UAC Disabled mediumstable
Author: frack113 · 2022-01-05 (modified 2024-05-10) · logsource: product=windows category=registry_set · 48437c39-9e5f-47fb-af95-3d663c3f2919
Detects when an attacker tries to disable User Account Control (UAC) by setting the registry value "EnableLUA" to 0.
Techniques: T1548.002
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-07-03 · logsource: product=windows category=file_event · 48ea844d-19b1-4642-944e-fe39c2cc1fec
Detects the creation of a file by "dllhost.exe" in System32 directory part of "IDiagnosticProfileUAC" UAC bypass technique
Techniques: T1548.002

All 56 rules on the technique page →

T1565 Data Manipulation primary impact

Sigma rules tagged attack.t1565 (3)

Author: Sittikorn S · 2021-06-29 (modified 2021-08-20) · logsource: product=aws service=cloudtrail · 16124c2d-e40b-4fcc-8f2c-5ab7870a2223
Identifies disabling of default Amazon Elastic Block Store (EBS) encryption in the current region. Disabling default encryption does not change the encryption status of your existing volumes.
Techniques: T1486T1565
Author: Austin Songer @austinsonger · 2021-08-15 (modified 2022-10-09) · logsource: product=gcp service=gcp.audit · 234f9f48-904b-4736-a34c-55d23919e4b7
Identifies when sensitive information is re-identified in google Cloud.
Techniques: T1565
Author: Borna Talebi · 2021-09-14 (modified 2022-10-09) · logsource: product=windows category=ps_script · 4368354e-1797-463c-bc39-a309effbe8d7
Detects powershell scripts that adds a Name Resolution Policy Table (NRPT) rule for the specified namespace. This will bypass the default DNS server and uses a specified server for answering the query.
Techniques: T1565