Executive brief
A vulnerability in the Windows NTLM authentication protocol allows an unauthorized attacker to access sensitive information. This flaw could be used to impersonate legitimate users or systems over a network, potentially leading to unauthorized access to corporate resources. Successful exploitation requires a user to interact with a malicious link or service.
Technical details
An information disclosure vulnerability exists in Windows NTLM (NT LAN Manager) authentication. The flaw, classified as CWE-200, allows an unauthenticated attacker to capture sensitive data that can be leveraged for network-based spoofing attacks. The attack vector is network-based and requires user interaction, such as a user visiting a malicious website or clicking a link. By exploiting this weakness, an attacker can gain high-confidentiality information without requiring prior administrative privileges. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows NTLM
Timeline
- 2026-06-09: advisory: Microsoft published the vulnerability details and security update.