Executive brief
A spoofing vulnerability in the Microsoft Windows Local Security Authority (LSA) allows an unauthenticated attacker to call a method on the LSARPC interface. This can be used to coerce a domain controller to authenticate against a remote server using NTLM, facilitating further attacks.
Affected products
- Microsoft Windows Server 2008 Service Pack 2
- Microsoft Windows Server 2008 R2 Service Pack 1
- Microsoft Windows Server 2012
- Microsoft Windows Server 2012 R2
- Microsoft Windows Server 2016 up to (excluding) 10.0.14393.4583
- Microsoft Windows Server 2019 up to (excluding) 10.0.17763.2114
- Microsoft Windows Server 2004 up to (excluding) 10.0.19041.1165
- Microsoft Windows Server 20H2 up to (excluding) 10.0.19042.1165
Timeline
- 2021-08-12: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: advisory: Advisory published date provided in report
- 2021-11-17: other: CISA Due Date for remediation