Vulnerability record · CVE-2021-36942 · published 12 August 2021
CVE-2021-36942: Windows LSA spoofing allows credential relay and NTLM coercion
Microsoft · Windows Server 2004
CVE-2021-36942 is a spoofing flaw in the Windows Local Security Authority (LSA) affecting multiple Windows Server releases. It is the vulnerability patched alongside the PetitPotam NTLM relay technique, which lets an unauthenticated attacker coerce a domain controller to authenticate to an attacker-controlled host and relay that authentication. Because it enables full domain takeover in common configurations, it is a high-value target for ransomware operators.
Description
Windows LSA Spoofing Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityIt is in CISA KEV with known ransomware use, has a very high EPSS score, and enables full domain compromise without authentication.
What it is
CVE-2021-36942 is a spoofing flaw in the Windows Local Security Authority (LSA) affecting multiple Windows Server releases. It is the vulnerability patched alongside the PetitPotam NTLM relay technique, which lets an unauthenticated attacker coerce a domain controller to authenticate to an attacker-controlled host and relay that authentication. Because it enables full domain takeover in common configurations, it is a high-value target for ransomware operators.
Impact
An attacker who relays the coerced authentication can impersonate a domain controller and obtain domain controller certificates or machine account credentials, leading to full Active Directory compromise. The CVSS vector indicates high confidentiality impact with no integrity or availability impact from the flaw itself.
Attack surface
Reachable over the network with no authentication and no user interaction (AV:N/AC:L/PR:N/UI:N). The attacker only needs network access to the target and a service that can be coerced into authenticating, such as the EFSRPC interface.
Exploitation
Listed in CISA KEV with a due date of 2021-11-17 and flagged for known ransomware campaign use; EPSS 30-day probability is 0.66023 (99.2nd percentile). A public exploit reference is available via the CERT/CC advisory.
What to do
- Apply the Microsoft August 2021 security updates for all affected Windows Server versions immediately.
- Disable or restrict NTLM authentication where feasible and enforce Extended Protection for Authentication and SMB signing.
- Block the EFSRPC and related coercion vectors at the network perimeter and between internal segments.
- Enable Active Directory Certificate Services protections, including requiring strong certificate mapping and disabling vulnerable enrollment endpoints.
- Monitor for and rotate any domain controller or machine account credentials that may have been relayed.
Detection
- Alert on unexpected NTLM authentication attempts to domain controllers from non-domain-controller hosts.
- Monitor for EFSRPC or similar RPC calls originating from untrusted systems.
- Audit certificate enrollment events for anomalous domain controller certificate requests.
- Correlate KEV-listed exploitation indicators with endpoint and network telemetry for relay activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-36942 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36942 | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-36942 | PatchVendor Advisory |
| https://www.kb.cert.org/vuls/id/405600 | ExploitThird Party AdvisoryUS Government Resource |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-36942 | US Government Resource |
Track CVE-2021-36942 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-36942), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.