CVE-2021-36942
KEV ransomware PoC massUnauthenticated LSA Spoofing (PetitPotam NTLM Relay) in Microsoft Windows
CISA: Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability
CVE-2021-36942 is a spoofing flaw in the Windows Local Security Authority (LSA), widely known as "PetitPotam," that lets an unauthenticated network attacker trick a Windows host into authenticating with NTLM to a machine the attacker controls. It is triggered remotely with no privileges and no user interaction (CVSS 3.1 AV:N/AC:L/PR:N/UI:N) by sending crafted requests that coerce the target system to authenticate. By relaying that coerced authentication to other services, an attacker can impersonate the machine — most critically a domain controller — and escalate toward domain-administrator access, producing a high confidentiality impact. All listed Windows Server releases are affected, with domain controllers and certificate-services servers as the highest-value targets. The flaw is actively exploited in the wild: it was added to CISA's KEV on 2021-11-03 with known ransomware use (LockFile and Babuk campaigns chained it with Exchange flaws), and Microsoft has released Windows updates to address it.
What to do: Apply Microsoft's Windows updates per vendor instructions, prioritizing domain controllers and servers running Active Directory Certificate Services. As interim hardening, require SMB signing and restrict NTLM authentication per Microsoft guidance, and review authentication logs for unexpected NTLM connections from domain controllers to certificate-services endpoints.
| Microsoft Windows (per CISA affected listing) | as listed by CISA |
| Microsoft Windows Server 2004 | as listed in CISA/CPE data |
| Microsoft Windows Server 2008 | as listed in CISA/CPE data |
| Microsoft Windows Server 2012 | as listed in CISA/CPE data |
| Microsoft Windows Server 2016 | as listed in CISA/CPE data |
| Microsoft Windows Server 2019 | as listed in CISA/CPE data |
| Microsoft Windows Server 20H2 | as listed in CISA/CPE data |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows LSA Spoofing Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows server 2004, windows server 2008, windows server 2012, windows server 2016, windows server 2019, windows server 20h2
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N