CVE-2022-26925: Windows LSA Spoofing Vulnerability
Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20371Fixed in 6.3.9600.20365Patch KB5014001 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.23714Patch KB5014018 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.21481Patch KB5014006 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.25954Patch KB5013999 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20367Patch KB5014025 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.5125Patch KB5013952 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.19297Patch KB5013963 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.675Patch KB5013943 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.1706Patch KB5013942 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.1706Patch KB5013942 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.1706Patch KB5013942 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.707Patch KB5013944 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.2274Patch KB5013945 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.2928Patch KB5013941 - Upgrade
Upgrade
Microsoft Windowsto a version that resolves this vulnerability.Fixed in 10.0.10240.19297Patch KB5013963 - Upgrade
Upgrade
Microsoft Windowsto a version that resolves this vulnerability.Fixed in 10.0.14393.5125Patch KB5013952 - Upgrade
Upgrade
Microsoft Windowsto a version that resolves this vulnerability.Fixed in 10.0.17763.2928Patch KB5013941 - Upgrade
Upgrade
Microsoft Windowsto a version that resolves this vulnerability.Fixed in 10.0.18363.2274Patch KB5013945 - Upgrade
Upgrade
Microsoft Windowsto a version that resolves this vulnerability.Fixed in 10.0.19042.1706Patch KB5013942 - Upgrade
Upgrade
Microsoft Windowsto a version that resolves this vulnerability.Fixed in 10.0.19043.1706Patch KB5013942 - Upgrade
Upgrade
Microsoft Windowsto a version that resolves this vulnerability.Fixed in 10.0.19044.1706Patch KB5013942 - Upgrade
Upgrade
Microsoft Windowsto a version that resolves this vulnerability.Fixed in 10.0.20348.707Patch KB5013944 - Upgrade
Upgrade
Microsoft Windowsto a version that resolves this vulnerability.Fixed in 10.0.22000.675Patch KB5013943 - Upgrade
Upgrade
Microsoft Windowsto a version that resolves this vulnerability.Fixed in 6.0.6003.21481Patch KB5014006 - Upgrade
Upgrade
Microsoft Windowsto a version that resolves this vulnerability.Fixed in 6.1.7601.25954Patch KB5013999 - Upgrade
Upgrade
Microsoft Windowsto a version that resolves this vulnerability.Fixed in 6.2.9200.23714Patch KB5014018 - Upgrade
Upgrade
Microsoft Windowsto a version that resolves this vulnerability.Fixed in 6.3.9600.20367Patch KB5014025 - Upgrade
Upgrade
Microsoft Windowsto a version that resolves this vulnerability.Fixed in 6.3.9600.20371Patch KB5014001 - Upgrade
Upgrade
Microsoft Windowsto a version that resolves this vulnerability.Fixed in 6.3.9600.20365Patch KB5014001
Event History
Frequently Asked Questions
What is the severity of CVE-2022-26925?
CVE-2022-26925 is a critical spoofing vulnerability in Microsoft Windows Local Security Authority that could allow an attacker to impersonate a domain controller.
How do I fix CVE-2022-26925?
To mitigate CVE-2022-26925, apply the latest security updates from Microsoft for affected Windows versions.
What versions of Windows are affected by CVE-2022-26925?
CVE-2022-26925 affects multiple versions of Windows, including Windows 10, Windows 11, and several Windows Server editions.
Could CVE-2022-26925 impact my organization's security?
Yes, CVE-2022-26925 can severely compromise the integrity of domain authentication within an organization.
Is there a known exploit for CVE-2022-26925?
As of the latest updates, there are no public exploits reported for CVE-2022-26925, but the vulnerability is critical and should be patched immediately.