Exploited· due 2022-07-22

CVE-2022-26925

Microsoft Windows

Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM.

Exploitation status

  • CISA has confirmed this is being exploited in the wild. That is an observation of real attacks, not a prediction.
  • US federal civilian agencies are required to remediate it by 2022-07-22. That deadline does not bind private companies, but it is a reasonable benchmark for how urgently CISA views it.

Required action

Apply remediation actions outlined in CISA guidance [https://www.cisa.gov/guidance-applying-june-microsoft-patch].

CISA’s wording, unedited.

Scoring

CVSS
Not yet scored

Dates

Published
2022-07-01
Added to KEV
2022-07-01
Remediation due
2022-07-22
Sources
CISA KEV