Executive brief
The Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability that allows an unauthenticated attacker to coerce a domain controller to authenticate to them via NTLM. This flaw can be leveraged to facilitate NTLM relay attacks against sensitive infrastructure.
Affected products
- Microsoft Windows 10 up to (excluding) 10.0.10240.19297
- Microsoft Windows 11 up to (excluding) 10.0.22000.675
- Microsoft Windows Server 2022
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1
- Microsoft Windows Server 2008
- Microsoft Windows Server 2012
- Microsoft Windows Server 2016
Timeline
- 2022-07-01: disclosed
- 2022-07-01: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-07-01: exploited: Reported as exploited in the wild at time of publication.