ZeroHour

CVE-2021-36942

KEV ransomware PoC mass

Unauthenticated LSA Spoofing (PetitPotam NTLM Relay) in Microsoft Windows

CISA: Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability

CVSS 3.1
7.5 high
EPSS
66%p99
Published
()
KEV added
AI analysis

CVE-2021-36942 is a spoofing flaw in the Windows Local Security Authority (LSA), widely known as "PetitPotam," that lets an unauthenticated network attacker trick a Windows host into authenticating with NTLM to a machine the attacker controls. It is triggered remotely with no privileges and no user interaction (CVSS 3.1 AV:N/AC:L/PR:N/UI:N) by sending crafted requests that coerce the target system to authenticate. By relaying that coerced authentication to other services, an attacker can impersonate the machine — most critically a domain controller — and escalate toward domain-administrator access, producing a high confidentiality impact. All listed Windows Server releases are affected, with domain controllers and certificate-services servers as the highest-value targets. The flaw is actively exploited in the wild: it was added to CISA's KEV on 2021-11-03 with known ransomware use (LockFile and Babuk campaigns chained it with Exchange flaws), and Microsoft has released Windows updates to address it.

What to do: Apply Microsoft's Windows updates per vendor instructions, prioritizing domain controllers and servers running Active Directory Certificate Services. As interim hardening, require SMB signing and restrict NTLM authentication per Microsoft guidance, and review authentication logs for unexpected NTLM connections from domain controllers to certificate-services endpoints.

Affected
Microsoft Windows (per CISA affected listing)as listed by CISA
Microsoft Windows Server 2004as listed in CISA/CPE data
Microsoft Windows Server 2008as listed in CISA/CPE data
Microsoft Windows Server 2012as listed in CISA/CPE data
Microsoft Windows Server 2016as listed in CISA/CPE data
Microsoft Windows Server 2019as listed in CISA/CPE data
Microsoft Windows Server 20H2as listed in CISA/CPE data
Estimated exposure
massmillions of Windows Server deployments; hundreds of thousands of SMB-exposed hosts in public internet scans — Windows Server is near-ubiquitous in enterprise environments (every Active Directory domain runs domain controllers susceptible to NTLM relay), and public internet scans consistently show hundreds of thousands of SMB-listening Windows…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows LSA Spoofing Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows server 2004, windows server 2008, windows server 2012, windows server 2016, windows server 2019, windows server 20h2
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news