CVE-2026-21249: Windows NTLM Spoofing Vulnerability
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.8868Patch KB5075999 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.6649Patch KB5075941 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.7840Fixed in 10.0.26100.7781Patch KB5077212 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2149Patch KB5075897 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.23022Patch KB5075970 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.6937Patch KB5075912 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.7840Fixed in 10.0.26200.7781Patch KB5077212 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.32370Fixed in 10.0.26100.32313Patch KB5075942 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.6937Patch KB5075912 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8389Patch KB5075904 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.4773Fixed in 10.0.20348.4711Patch KB5075943 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.1575Patch KB5077179
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21249?
CVE-2026-21249 is considered a critical vulnerability due to its potential for unauthorized access and local spoofing attacks.
How do I fix CVE-2026-21249?
To fix CVE-2026-21249, apply the relevant security updates provided by Microsoft for your specific Windows version or edition.
Which versions of Windows are affected by CVE-2026-21249?
CVE-2026-21249 affects multiple Windows versions including Windows Server 2012 R2, Windows Server 2025, Windows 10, and Windows 11 among others.
How can I determine if my system is vulnerable to CVE-2026-21249?
You can determine vulnerability by checking if your Windows system is running an affected version and if it has the required updates installed.
What impact does CVE-2026-21249 have on Windows systems?
CVE-2026-21249 allows an unauthorized attacker to locally spoof accounts, potentially compromising the integrity of the system.