MEDIUM

CVE-2022-26925

Microsoft Windows 10 1507 2022-05-10 CVSS v3.1
CVSS
5.9
KEV

Description

Windows LSA Spoofing Vulnerability

Summary dbcve.org

Windows LSA Spoofing Vulnerability in the Local Security Authority (LSA) subsystem that allows an attacker to potentially impersonate legitimate users or systems through spoofing attacks against the Windows authentication mechanisms.

Mitigation

Apply Microsoft security updates for this vulnerability. Ensure Windows systems are patched with the latest cumulative updates. For systems where immediate patching is not feasible, implement network segmentation and restrict privileged access to mitigate potential exploitation.

Patch Commit

Weakness (CWE)

CWE-306 Missing Authentication

EPSS Score

10.72%
Probability of exploitation in next 30 days
95.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE