Junglewise Threat Intelligence

CVE-2021-36942: Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability

CVE-2021-36942 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Windows Server 2016, Microsoft Windows, Microsoft Windows Server 2012 R2, Microsoft Windows Server 2012, Microsoft Windows Server 2008 R2, Microsoft Windows Server 2008, Microsoft Windows Server 2019. Vendors: Microsoft.

Executive brief

A spoofing vulnerability in the Microsoft Windows Local Security Authority (LSA) allows an unauthenticated attacker to call a method on the LSARPC interface. This can be used to coerce a domain controller to authenticate against a remote server using NTLM, facilitating further attacks.

Affected products

  • Microsoft Windows Server 2008 Service Pack 2
  • Microsoft Windows Server 2008 R2 Service Pack 1
  • Microsoft Windows Server 2012
  • Microsoft Windows Server 2012 R2
  • Microsoft Windows Server 2016 up to (excluding) 10.0.14393.4583
  • Microsoft Windows Server 2019 up to (excluding) 10.0.17763.2114
  • Microsoft Windows Server 2004 up to (excluding) 10.0.19041.1165
  • Microsoft Windows Server 20H2 up to (excluding) 10.0.19042.1165

Timeline

  • 2021-08-12: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: advisory: Advisory published date provided in report
  • 2021-11-17: other: CISA Due Date for remediation

Related threats