RaqibCTI
CVE

CVE-2022-26925

P2
Microsoft Windows LSA Spoofing Vulnerability
Microsoft · Windows
Date added (CISA)
2022-07-01
Remediation due
2022-07-22
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date

Description

Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM.

Source: NVD ↗ · CISA KEV Catalog ↗