{"id":"CVE-2022-26925","vendor_project":"Microsoft","product":"Windows","vulnerability_name":"Microsoft Windows LSA Spoofing Vulnerability","date_added":"2022-07-01","due_date":"2022-07-22","known_ransomware_use":"Unknown","short_description":"Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM.","required_action":"Apply remediation actions outlined in CISA guidance [https://www.cisa.gov/guidance-applying-june-microsoft-patch].","cwes":"CWE-306","cvss_version":"3.1","cvss_severity":"MEDIUM","cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","nvd_published":"2022-05-10","nvd_status":"Analyzed","epss":0.10721,"epss_percentile":0.95622,"cvss_score":5.9,"days_published_to_kev":52,"source":"https://data.cybermax-tools.workers.dev/cve/CVE-2022-26925","by":"CyberMax"}