cbcvebase.
CVE-2022-26925
published 2022-05-10

CVE-2022-26925: Windows LSA Spoofing Vulnerability Windows LSA Spoofing Vulnerability

medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2022-07-22
Exploited in the wild
EPSS
10.46%
95.2th percentile
Windows LSA Spoofing Vulnerability Windows LSA Spoofing Vulnerability

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux_kernel>= 0 < 5.4.0-187.2075.4.0-187.207
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.1929710.0.10240.19297
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.512510.0.14393.5125
microsoftwindows_10_version_1809>= 10.0.0 < 10.0.17763.292810.0.17763.2928
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.292810.0.17763.2928
microsoftwindows_10_version_1909>= 10.0.0 < 10.0.18363.227410.0.18363.2274
microsoftwindows_10_version_20h2>= 10.0.0 < 10.0.19042.170610.0.19042.1706
microsoftwindows_10_version_21h1>= 10.0.0 < 10.0.19043.170610.0.19043.1706
microsoftwindows_10_version_21h2>= 10.0.19043.0 < 10.0.19043.170610.0.19043.1706
microsoftwindows_11_version_21h2>= 10.0.0 < 10.0.22000.67510.0.22000.675
microsoftwindows_7>= 6.1.0 < 6.1.7601.259546.1.7601.25954
microsoftwindows_7_service_pack_1>= 6.1.0 < 6.1.7601.259546.1.7601.25954
microsoftwindows_8.1>= 6.3.0 < 6.3.9600.203716.3.9600.20371
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.7601.0 < 6.1.7601.259546.1.7601.25954
microsoftwindows_server_2008_service_pack_2>= 6.0.6003.0 < 6.0.6003.214816.0.6003.21481
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.237146.2.9200.23714
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.203716.3.9600.20371
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.512510.0.14393.5125
microsoftwindows_server_2019>= 10.0.17763.0 < 10.0.17763.292810.0.17763.2928
microsoftwindows_server_2022>= 10.0.20348.0 < 10.0.20348.70710.0.20348.707
microsoftwindows_server_version_20h2>= 10.0.0 < 10.0.19042.170610.0.19042.1706
msrcwindows_10
msrcwindows_10_version_1607
msrcwindows_10_version_1809
msrcwindows_10_version_1909

Detection & IOCsextracted from sources · hover to see the quote

  • Detect anonymous connection attempts on the LSARPC interface — the exploit coerces domain controller authentication via an unauthenticated LSARPC method call
  • Alert on NTLM authentication requests originating from domain controllers toward unexpected/attacker-controlled hosts — indicates active NTLM relay exploitation chained with CVE-2022-26925
  • Monitor for machine-in-the-middle (MITM) positioning on the logical network path between domain controllers and requested resources, as required by the attack's high-complexity precondition
  • Prioritize detection on domain controllers: CVE-2022-26925 exploitation has been confirmed in the wild on both latest and older software releases
  • Correlate CVE-2022-26925 NTLM coercion activity with NTLM Relay Attacks targeting Active Directory Certificate Services (AD CS) — chaining raises combined CVSSv3 to 9.8 and can lead to RCE
  • ·Applying the May 2022 patch to domain controllers without additional configuration changes breaks PIV/CAC (smart card) authentication — follow CISA implementation guidance before deploying to DCs
  • ·The EFS API OpenEncryptedFileRaw(A/W) used in backup software stops working on Windows Server 2008 SP2 after patching; all other Windows versions retain local and remote EFS backup functionality
  • ·Domain controllers must be patched on a priority basis before other servers due to the elevated risk of NTLM relay leading to remote code execution

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
cvelistv58.1HIGH
osv6.5MEDIUM
vulncheck8.1HIGH
cisa5.9MEDIUM
vendor_msrc8.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.