⚠ Actively exploited
Added to CISA KEV on 2022-07-01. Federal agencies required to patch by 2022-07-22. Required action: Apply remediation actions outlined in CISA guidance [https://www.cisa.gov/guidance-applying-june-microsoft-patch]..

CVE-2022-26925

Severity
8.1HIGH
No vector
EPSS
37.4%
top 2.82%
CISA KEV
KEV
Added 2022-07-01
Due 2022-07-22
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedMay 10
KEV addedJul 1
KEV dueJul 22
Latest updateJul 10
CISA Required Action: Apply remediation actions outlined in CISA guidance [https://www.cisa.gov/guidance-applying-june-microsoft-patch].

Description

Windows LSA Spoofing Vulnerability Windows LSA Spoofing Vulnerability

Affected Packages25 packages

CVEListV5microsoft/windows_76.1.06.1.7601.25954
CVEListV5microsoft/windows_8.16.3.06.3.9600.20371
CVEListV5microsoft/windows_server_20126.2.9200.06.2.9200.23714
CVEListV5microsoft/windows_server_201610.0.14393.010.0.14393.5125
CVEListV5microsoft/windows_server_201910.0.17763.010.0.17763.2928

🔴Vulnerability Details

5
OSV
linux-aws-5.4 vulnerabilities2024-07-10
OSV
linux, linux-aws, linux-azure, linux-azure-5.4, linux-bluefield, linux-gcp, linux-gkeop, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, lin2024-07-03
Project0
2022 0-day In-the-Wild Exploitation…so far - Project Zero2022-06-01
CVEList
Windows LSA Spoofing Vulnerability2022-05-10
VulnCheck
Microsoft Windows LSA Spoofing Vulnerability2022

📋Vendor Advisories

2
CISA
Microsoft Windows LSA Spoofing Vulnerability2022-07-01
Microsoft
Windows LSA Spoofing Vulnerability2022-05-10

🕵️Threat Intelligence

4
Unit42
Threat Brief: Microsoft Critical Vulnerabilities (CVE-2022-26809, CVE-2022-26923, CVE-2022-26925)2022-07-27
Unit42
Threat Brief: Microsoft Critical Vulnerabilities (CVE-2022-26809, CVE-2022-26923, CVE-2022-26925)2022-07-27
Krebs
Microsoft Patch Tuesday, May 2022 Edition2022-05-11
Krebs
Microsoft Patch Tuesday, May 2022 Edition2022-05-11
CVE-2022-26925 (HIGH CVSS 8.1) | Windows LSA Spoofing Vulnerability | cvebase.io