CVE detail
CVE-2022-26925
Windows LSA Spoofing Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 27.7 · diversity 19.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
15 source links · newest first
- Ridding your network of NTLMCSO Online
Microsoft has hinted at a possible end to NTLM a few times, but with quite a few Windows 95 or 98 in use that do not support the alternative, Kerberos, it won’t be an easy job to do. There is the option to disable NTLM when using Azure Active Directory but that may not always […]
newswww.csoonline.comJan 20, 2025, 7:00 AM Since introducing NTLM coercion techniques such as PetitPotam into the NodeZero platform, we frequently have security practitioners request help understanding these techniques and what impact they have to their enterprise. There is a lack of concise resources to inform Blue Teams on how these techniques work, and clearly distinguishing them from other misconfigurations/vulnerabilities in the […]
exploithorizon3.aiJan 9, 2024, 3:47 PM- In 2022, more than 40% of zero-day exploits used in the wild were variations of previous issuesSecurity Affairs
Google’s Threat Analysis Group Google states that more than 40% of zero-day flaws discovered in 2022 were variants of previous issues. The popular Threat Analysis Group (TAG) Maddie Stone wrote Google’s fourth annual year-in-review of zero-day flaws exploited in-the-wild [2021, 2020, 2019], it is built off of the mid-year 2022 review. In 2022, the researchers […]
newssecurityaffairs.comJul 30, 2023, 4:38 PM We soon close out the security year of 2022. Only time will tell what 2023 will bring, but for IT and security admins of Microsoft networks, 2022 has been the year of blended attacks, on-premises Exchange Server flaws, and vulnerabilities needing more than patching to mitigate. Here’s a month-by-month look at the past year. January: […]
newswww.csoonline.comDec 8, 2022, 10:00 AM- Threat Brief: Microsoft Critical Vulnerabilities (CVE-2022-26809, CVE-2022-26923, CVE-2022-26925)Unit42
We provide an overview of CVE-2022-26809, CVE-2022-26923 and CVE-2022-26925, along with recommendations for mitigation.
vendorunit42.paloaltonetworks.comJul 27, 2022, 11:00 PM - Security Affairs newsletter Round 373 by Pierluigi PaganiniSecurity Affairs
A new round of the weekly Security Affairs newsletter arrived! Every week the best security articles from Security Affairs for free in your email box. Apple Lockdown Mode will protect users against highly targeted cyberattacks Fortinet addressed multiple vulnerabilities in several products Rozena backdoor delivered by exploiting the Follina bug Ongoing Raspberry Robin campaign leverages […]
newssecurityaffairs.comJul 10, 2022, 2:41 PM - CISA orders federal agencies to patch CVE-2022-26925 by July 22Security Affairs
US Critical Infrastructure Security Agency (CISA) adds CVE-2022-26925 Windows LSA flaw to its Known Exploited Vulnerabilities Catalog. In May the US CISA removed the CVE-2022-26925 Windows LSA vulnerability from its Known Exploited Vulnerabilities Catalog due to Active Directory (AD) certificate authentication problems observed after the installation of Microsoft’s May 2022 Patch Tuesday security updates. “CISA […]
newssecurityaffairs.comJul 4, 2022, 7:16 AM - Half of actively exploited zero-day issues in H1 2022 are variants of previous flawsSecurity Affairs
Google Project Zero states that in H1 2022 at least half of zero-day issues exploited in attacks were related to not properly fixed old flaws. Google Project Zero researcher Maddie Stone published a blog post that resumes her speech at the FIRST conference in June 2022, the presentation is titled “0-day In-the-Wild Exploitation in 2022…so […]
newssecurityaffairs.comJul 3, 2022, 1:31 PM Google Project Zero has observed a total of 18 exploited zero-day vulnerabilities in the first half of 2022, at least half of which exist because previous bugs were not properly addressed.
newswww.securityweek.comJul 1, 2022, 11:12 AMIf you are as old as I am, you remember when you first had to deal with domains and Active Directory (AD). Even if you aren’t as old as I am, you still probably must deal with domains and Active Directory. If you are just starting out at a new firm, you probably know only […]
newswww.csoonline.comMay 25, 2022, 9:00 AMThe US Cybersecurity and Infrastructure Security Agency (CISA) has temporarily removed a Windows flaw from its Known Exploited Vulnerabilities Catalog after it was informed by Microsoft that a recent update can cause problems on some types of systems.
newswww.securityweek.comMay 16, 2022, 11:16 AM- Week in review: F5 BIG-IP RCE exploitation, URL spoofing flaws in Zoom, Google DocsHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles and interviews: Microsoft patches Windows LSA spoofing zero-day under active attack (CVE-2022-26925) May 2022 Patch Tuesday is here, and Microsoft has marked it by releasing fixes for 74 CVE-numbered vulnerabilities, including one zero-day under active attack (CVE-2022-26925) and two publicly known vulnerabilities (CVE-2022-29972 and CVE-2022-22713). Attackers are attempting to exploit critical F5 BIG-IP RCE Researchers have developed PoC exploits for CVE-2022-1388, a critical … More →
newswww.helpnetsecurity.comMay 15, 2022, 8:30 AM - Microsoft Patch Tuesday updates for May 2022 fixes 3 zero-days, 1 under active attackSecurity Affairs
Microsoft Patch Tuesday security updates for May 2022 address three zero-day vulnerabilities, one of them actively exploited. Microsoft Patch Tuesday security updates for May 2022 addressed three zero-day vulnerabilities, one of which is under active attack. The IT giant fixed a total of 74 flaws in Microsoft Windows and Windows Components, .NET and Visual Studio, […]
newssecurityaffairs.comMay 11, 2022, 6:11 AM - Microsoft patches Windows LSA spoofing zero-day under active attack (CVE-2022-26925)Help Net Security
May 2022 Patch Tuesday is here, and Microsoft has marked it by releasing fixes for 74 CVE-numbered vulnerabilities, including one zero-day under active attack (CVE-2022-26925) and two publicly known vulnerabilities (CVE-2022-29972 and CVE-2022-22713). Vulnerabilities of particular note First and foremost, we have CVE-2022-26925, an “important” spoofing vulnerability in Windows Local Security Authority (LSA) that may turn into a “critical” one if combined with NTLM relay attacks. “Being actively exploited in the wild, this [vulnerability] allows … More →
newswww.helpnetsecurity.comMay 10, 2022, 7:10 PM Microsoft on Tuesday released critical software updates to fix at least 73 documented security flaws in the Windows ecosystem and warned that unknown attackers are already launching zero-day man-in-the-middle attacks.
newswww.securityweek.comMay 10, 2022, 6:22 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2022-26904CVSS 7.0 · High
Windows User Profile Service Elevation of Privilege Vulnerability
- CVE-2022-24521CVSS 7.8 · High
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2022-22718CVSS 7.8 · High
Windows Print Spooler Elevation of Privilege Vulnerability
KEV listed4 mentions - CVE-2022-21999CVSS 7.8 · High
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-21919CVSS 7.0 · High
Windows User Profile Service Elevation of Privilege Vulnerability
- CVE-2021-43226CVSS 7.8 · High
Windows Common Log File System Driver Elevation of Privilege Vulnerability
KEV listed3 mentions