Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Jul 22, 2022

CVE-2022-26925

High
EPSS 37.4%CISA KEV
Microsoft/Windows

Description

Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM.

EPSS — Exploit Probability

37.4%

Higher than 97.1% of all CVEs

Required Action

WARNING: This update is required on all Microsoft Windows endpoints but if deployed to domain controllers without additional configuration changes the update breaks PIV/CAC authentication. Read CISA implementation guidance carefully before deploying to domain controllers.; https://nvd.nist.gov/vuln/detail/CVE-2022-26925

Risk Assessment

ELEVATED
In CISA KEV

Details

Severity
High
EPSS
37.4%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Jul 1, 2022

Added to KEV

Jul 1, 2022

Remediation Due

Jul 22, 2022

Affected Product

Microsoft

Windows

View all Microsoft CVEs