CISA Known Exploited Vulnerability

CVE-2022-26925

Microsoft · Windows

Microsoft Windows LSA Spoofing Vulnerability

Date added
BOD 22-01 due date
CWE CWE-306
Ransomware Unknown

CISA description

Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM.

Required action

Apply remediation actions outlined in CISA guidance [https://www.cisa.gov/guidance-applying-june-microsoft-patch].

Notes & references