← back
CVE-2022-26925

Windows LSA Spoofing Vulnerability

CVSS 8.1 HIGHEPSS 9.8%● KEVCWE-306
In short

A spoofing vulnerability in Windows Local Security Authority (LSA) allows an attacker to impersonate legitimate security credentials or processes. This could enable unauthorized access to sensitive data or system resources by tricking the system into trusting false security claims.

Technical detail

The vulnerability in Windows LSA (CWE-306: Missing Authentication) permits an attacker to forge or spoof authentication credentials without proper verification. An authenticated or local attacker can manipulate LSA validation mechanisms to impersonate privileged users or processes, potentially gaining elevated access or bypassing security policy enforcement.

Summary generated and translated by AI from the official description.
Windows LSA Spoofing Vulnerability
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →