Vulnerability record · CVE-2022-26925 · published 10 May 2022
CVE-2022-26925: Windows LSA spoofing via missing authentication
Microsoft · Windows 10 1507
CVE-2022-26925 is a spoofing flaw in the Windows Local Security Authority (LSA) caused by missing authentication for a critical function (CWE-306). An unauthenticated network attacker can impersonate a legitimate service or domain controller, which matters because LSA handles authentication and trust decisions across Windows clients and servers.
Description
Windows LSA Spoofing Vulnerability
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Automated analysis
high priorityIt is confirmed exploited in CISA KEV and affects a broad range of Windows versions, but the High attack complexity and integrity-only impact keep it below critical.
What it is
CVE-2022-26925 is a spoofing flaw in the Windows Local Security Authority (LSA) caused by missing authentication for a critical function (CWE-306). An unauthenticated network attacker can impersonate a legitimate service or domain controller, which matters because LSA handles authentication and trust decisions across Windows clients and servers.
Impact
An attacker gains the ability to spoof a trusted authentication endpoint, potentially intercepting or manipulating authentication traffic and enabling follow-on credential theft or relay attacks. The CVSS vector rates integrity impact as High with no confidentiality or availability impact.
Attack surface
Reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N), though the High attack complexity (AC:H) indicates a narrow or timing-dependent condition must be met. No local access or credentials are required.
Exploitation
Listed in CISA KEV with a remediation due date of 2022-07-22, confirming exploitation in the wild; EPSS 30-day probability is about 10.7 percent (95.6th percentile). No ransomware campaign use is documented in the record.
What to do
- Apply the Microsoft May 2022 security updates for all affected Windows client and server versions, prioritizing domain controllers.
- Follow CISA's June 2022 Microsoft patch guidance referenced in the KEV entry.
- Enforce SMB signing and Extended Protection for Authentication (EPA) on domain controllers to blunt relay and spoofing attempts.
- Restrict network exposure of authentication services (RPC, SMB, LDAP) to trusted segments and monitor for anomalous DC authentication traffic.
- Audit for unpatched legacy systems (Windows 7, 8.1, Server 2008/2012) that may no longer receive updates and isolate them.
Detection
- Monitor Windows event logs for anomalous NTLM or Kerberos authentication attempts against domain controllers, especially from unexpected source hosts.
- Hunt for authentication relay indicators such as repeated failed logons followed by successful authentication from the same source.
- Alert on unexpected RPC or SMB connections to domain controllers from non-administrative workstations.
- Correlate network traffic to LSA-related ports with hosts that have not applied the May 2022 patch baseline.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-26925 to the Known Exploited Vulnerabilities catalog on 1 July 2022 as "Microsoft Windows LSA Spoofing Vulnerability". Required action: Apply remediation actions outlined in CISA guidance [https://www.cisa.gov/guidance-applying-june-microsoft-patch]. Federal deadline 22 July 2022.
Affected products
17 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26925 | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-26925 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-26925 | US Government Resource |
Track CVE-2022-26925 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-26925), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.