﻿# V5014\. OWASP\. Cryptographic function is deprecated\. Its use can lead to security issues\. Consider switching to an equivalent newer function\.

The analyzer has detected a call to a deprecated cryptographic function\. The use of this function can cause security issues\.

Let's look at the following example:

```cpp
BOOL ImportKey(HCRYPTPROV hProv, LPBYTE pbKeyBlob, DWORD dwBlobLen)
{
  HCRYPTKEY hPubKey;
  if (!CryptImportKey(hProv, pbKeyBlob, dwBlobLen, 0, 0, &hPubKey))
  {
    return FALSE;
  }
  if (!CryptDestroyKey(hPubKey))
  {
    return FALSE;
  }
  return TRUE;
}
```

According to the Microsoft documentation, the '[CryptoImportKey](https://learn.microsoft.com/en-us/windows/win32/api/wincrypt/nf-wincrypt-cryptimportkey)' and '[CryptoDestroyKey](https://learn.microsoft.com/en-us/windows/win32/api/wincrypt/nf-wincrypt-cryptdestroykey)' functions are deprecated\. They should be replaced with secure analogs from [Cryptography Next Generation](https://learn.microsoft.com/en-us/windows/win32/seccng/cng-portal) \('[BCryptoImportKey](https://learn.microsoft.com/en-us/windows/win32/api/bcrypt/nf-bcrypt-bcryptimportkey)' and '[BCryptoDestroyKey](https://learn.microsoft.com/en-us/windows/win32/api/bcrypt/nf-bcrypt-bcryptdestroykey)'\):

```cpp
BOOL ImportKey(BCRYPT_ALG_HANDLE  hAlgorithm,
               BCRYPT_ALG_HANDLE  hImportKey,
               BCRYPT_KEY_HANDLE* phKey,
               PUCHAR             pbInput, 
               ULONG              cbInput, 
               ULONG              dwFlags)
{
  if (!BCryptImportKey(
         hAlgorithm,
         hImportKey,
         BCRYPT_AES_WRAP_KEY_BLOB,
         phKey,
         NULL,
         0,
         pbInput,
         cbInput,
         dwFlags))
  {
    return FALSE;
  }

  if (!BCryptDestroyKey(phKey))
  {
    return FALSE;
  }
  return TRUE;
}
```

This diagnostic rule applies to deprecated cryptographic functions of the [Windows API](https://learn.microsoft.com/en-us/windows/win32/seccrypto/cryptography-functions), [Linux Kernel Crypto API](https://www.kernel.org/doc/html/v5.4/crypto/), and [GnuPG Made Easy](https://www.gnupg.org/software/gpgme/index.html)\.

If you need to mark up unwanted functions yourself, use the [function annotation mechanism](https://pvs-studio.com/en/docs/manual/6743/) and the [V2016](https://pvs-studio.com/en/docs/warnings/v2016/) diagnostic rule\.