Executive brief
A spoofing vulnerability exists in the Windows NTLM authentication protocol, which is used to verify user identities across corporate networks. An attacker could exploit this to trick a system into interacting with a malicious file path, potentially leading to the unauthorized disclosure of sensitive information. This could allow an attacker to impersonate legitimate users or services, compromising the integrity of network communications.
Technical details
A spoofing vulnerability exists in Windows NTLM due to improper validation of user-supplied input affecting file names or paths (CWE-73). An unauthenticated attacker can exploit this over the network by inducing a user to perform a specific action, such as clicking a link or visiting a malicious site (User Interaction required). Successful exploitation allows the attacker to control file paths used by the NTLM protocol, which can be leveraged for spoofing attacks or sensitive information disclosure. Microsoft has released security updates to address this vulnerability across multiple versions of Windows and Windows Server.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 22H2, 23H2, 24H2, 25H2
- Microsoft Windows Server 2008 R2 Service Pack 1
Timeline
- 2026-01-13: disclosed
- 2026-01-13: advisory: Microsoft released vendor advisory