CVE-2022-26925CISA KEV
Microsoft Windows LSA Spoofing Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM.
- Product
- Windows
- Added to KEV
- 1 Jul 2022
- Federal remediation due
- 22 Jul 2022
- Known ransomware use
- Not reported