CVE-2026-21249: Windows NTLM Spoofing Vulnerability
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21249?
CVE-2026-21249 is considered a critical vulnerability due to its potential for unauthorized access and local spoofing attacks.
How do I fix CVE-2026-21249?
To fix CVE-2026-21249, apply the relevant security updates provided by Microsoft for your specific Windows version or edition.
Which versions of Windows are affected by CVE-2026-21249?
CVE-2026-21249 affects multiple Windows versions including Windows Server 2012 R2, Windows Server 2025, Windows 10, and Windows 11 among others.
How can I determine if my system is vulnerable to CVE-2026-21249?
You can determine vulnerability by checking if your Windows system is running an affected version and if it has the required updates installed.
What impact does CVE-2026-21249 have on Windows systems?
CVE-2026-21249 allows an unauthorized attacker to locally spoof accounts, potentially compromising the integrity of the system.