LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-26925: Microsoft Windows LSA Spoofing Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 1, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 22, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-26925 to its Known Exploited Vulnerabilities catalog on Jul 1, 2022, with a federal patch deadline of Jul 22, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM.

CVE-2022-26925 is a spoofing vulnerability in the Local Security Authority (LSA) component of Microsoft Windows. An attacker can coerce a domain controller to authenticate to the attacker using NTLM. This matters because successful abuse can undermine domain authentication trust and enable further lateral movement or credential abuse inside Windows environments. Confirm all product and configuration details against the vendor advisory and related CISA guidance.

How it works

The weakness is classed as CWE-306 (Missing Authentication for Critical Function). In plain terms, the LSA path involved does not adequately ensure that a critical authentication-related action is properly authenticated before proceeding. Per the CISA summary, an attacker can coerce the domain controller to authenticate to the attacker using NTLM. This is a spoofing issue: the attacker tricks the domain controller into treating the attacker-controlled endpoint as a legitimate authentication target. Exact exploit mechanics, required privileges, and network preconditions are not detailed here and must be confirmed against the Microsoft advisory. Defenders should treat this as an NTLM coercion / authentication-spoofing class problem against domain controllers and related Windows hosts that participate in LSA authentication flows.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows. Domain controllers are the primary concern given the described coercion of domain-controller NTLM authentication, but inventory all Windows systems that run LSA-related authentication services and participate in domain authentication.

How to remediate

Patch first. Apply the remediation actions outlined in CISA guidance for the June Microsoft updates and the corresponding Microsoft security update for CVE-2022-26925. Confirm the exact packages and reboot requirements in the vendor advisory before deployment.

If you can't patch immediately

Use compensating controls to lower the chance of successful coercion until patches are applied.

If your data may have been exposed

Actively exploited authentication vulnerabilities can lead to domain compromise and subsequent data exposure even when ransomware use is not documented for this CVE. If you suspect coercion or unauthorized authentication activity, follow incident-response procedures: isolate affected systems, reset relevant credentials, and review domain authentication logs. You can also run a free exposure scan of your email addresses against known breach data to check whether associated accounts appear in prior breaches.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-306
Added to CISA KEVJul 1, 2022
Federal patch deadlineJul 22, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities