Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability
Microsoft · Windows
Date added (CISA)
2021-11-03
Remediation due
2021-11-17
Known ransomware use
Yes
Remediation priority
P1 — known ransomware use · past CISA due date
Description
Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to authenticate against another server using NTLM.