CVE-2022-26925—Microsoft Windows LSA Spoofing Vulnerability
PUBLISHEDvulnerability record
2022-07-01 · last modified June 21, 2025
Metadata
Vulnerability Name
Microsoft Windows LSA Spoofing Vulnerability
Description
Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM.
Known To Be Used in Ransomware Campaigns?
Action
Apply remediation actions outlined in CISA guidance [https://www.cisa.gov/guidance-applying-june-microsoft-patch].