MEDIUM
CVE-2022-26925
CVSS
5.9
KEV
Description
Windows LSA Spoofing Vulnerability
Summary dbcve.org
Windows LSA Spoofing Vulnerability in the Local Security Authority (LSA) subsystem that allows an attacker to potentially impersonate legitimate users or systems through spoofing attacks against the Windows authentication mechanisms.
Mitigation
Apply Microsoft security updates for this vulnerability. Ensure Windows systems are patched with the latest cumulative updates. For systems where immediate patching is not feasible, implement network segmentation and restrict privileged access to mitigate potential exploitation.
Weakness (CWE)
CWE-306
Missing Authentication
EPSS Score
10.72%
Probability of exploitation in next 30 days
95.7th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26925
Patch, Vendor Advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-26925
Patch, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-26925
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.