Executive brief
A security vulnerability exists in the way Windows handles network authentication (NTLM). An attacker could trick a user into visiting a malicious site or opening a file that forces the computer to send authentication data to an unauthorized location. This could allow the attacker to impersonate the user or gain unauthorized access to sensitive information on the network.
Technical details
A vulnerability classified as CWE-73 (External Control of File Name or Path) exists in the Windows NTLM implementation. The flaw allows an unauthenticated, remote attacker to influence file paths used during NTLM authentication processes. By inducing a user to interact with a malicious link or resource (User Interaction required), the attacker can trigger NTLM spoofing. This typically results in the disclosure of NTLM hashes or unauthorized credential relaying. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
- Microsoft Windows Server 2008 R2 Service Pack 1
Timeline
- 2026-01-13: advisory: Initial disclosure by Microsoft and NVD
- 2026-07-30: patched: Last modified/updated record in MSRC guide