Microsoft patches Windows LSA spoofing zero-day under active attack (CVE-2022-26925)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-22713 | Windows Hyper-V Denial of Service Vulnerability Windows Hyper-V Denial of Service Vulnerability NVD description · AI analysis pending | 5.6 | <1% |
| — | ||
| CVE-2022-26923 | Authenticated Privilege Escalation in Microsoft Active Directory Domain Services CVE-2022-26923 is an elevation-of-privilege flaw in Microsoft Active Directory Domain Services (CWE-295, improper certificate validation), widely known as the 'sAMAccountName spoofing' issue. An attacker with ordinary domain-user credentials can create or rename a computer account so its sAMAccountName matches a domain controller's name, obtain a certificate for that account, and use the flawed certificate-to-account name mapping to authenticate as that domain controller. Successful exploitation grants the attacker Domain Admin privileges and effectively full control over the Active Directory forest. Any organization running AD DS on the affected Windows 10/11, Windows 8.1, Windows RT 8.1, or Windows Server releases is exposed until patched. The flaw was fixed in Microsoft's May 2022 Patch Tuesday updates and is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-08-18, EPSS puts its 30-day exploitation probability at 83.5% (100th percentile), no public PoC is cataloged, and ransomware use is unknown. Do: Apply Microsoft's May 2022 security updates (or later cumulative updates) to every domain controller and affected Windows/Windows Server host, prioritizing domain controllers, and verify patch status fleet-wide. Until patched, audit recently created or renamed computer accounts whose sAMAccountName matches a domain controller name, restrict which users can add machine accounts, and monitor for unusual certificate-based logons by privileged accounts. Patching is required for U.S. federal agencies since the flaw is in CISA's KEV catalog (required action: apply updates per vendor instructions). | 8.8 | 84% | KEV |
| massmillions of domain-joined systems across effectively all enterprise AD forests that had not yet applied the May 2022 updates | |
| CVE-2022-26925 | Spoofing Flaw in Windows LSA (CVE-2022-26925) Exploited Against Domain Controllers CVE-2022-26925 is a spoofing vulnerability in the Windows Local Security Authority (LSA) that lets an unauthenticated network attacker make a spoofed call to LSA on a remote Windows host. It is triggered over the network with no user interaction, typically by coercing a Windows system—most critically a domain controller—into authenticating via NTLM to an attacker-controlled machine, in the manner of the PetitPotam forced-authentication attacks referenced in CISA's catalog update. By spoofing the client when LSA processes that authentication, the attacker undermines NTLM's authentication guarantees and, when chained with relay techniques, can authenticate to a domain controller with elevated privileges, which is reflected in the CVSS high-integrity impact. Any organization running affected Windows clients or Windows Server versions is exposed, with domain controllers the highest-value targets. The flaw was exploited as a zero-day before Microsoft's June 2022 Patch Tuesday fixes and is now listed in CISA's Known Exploited Vulnerabilities catalog, with CISA ordering federal agencies to patch. Do: Apply Microsoft's June 2022 Patch Tuesday updates (per CISA's guidance for the June Microsoft patch, https://www.cisa.gov/guidance-applying-june-microsoft-patch) across all affected Windows versions, prioritizing domain controllers; systems that cannot yet patch should be protected with NTLM-related mitigations (e.g., enforced SMB signing, LDAP signing/channel binding, and restricting or auditing NTLM use) per CISA/Microsoft remediation guidance. Check whether domain controllers are internet-exposed or reachable from untrusted networks, and hunt for signs of forced-authentication/relay activity. Note that a related PetitPotam KEV entry was superseded, so ensure this newer LSA fix—not just the older PetitPotam patch—is deployed. | 5.9 | 11% | KEV |
| mass≈1 billion+ Windows installations worldwide (essentially every Windows environment, and domain controllers at virtually every Windows-running organization) | |
| CVE-2022-26937 | Windows Network File System Remote Code Execution Vulnerability Windows Network File System Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.8 | 76% |
| — | ||
| CVE-2022-29972 | An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift ODBC Driver (1.4.14 through 1.4.21.1001 An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift ODBC Driver (1.4.14 through 1.4.21.1001 and 1.4.22 through 1.4.x before 1.4.52) may allow a local user to execute arbitrary code. NVD description · AI analysis pending | 7.8 | 4% |
| — |
Full article654 words · extracted from helpnetsecurity.com · click to collapse
May 2022 Patch Tuesday is here, and Microsoft has marked it by releasing fixes for 74 CVE-numbered vulnerabilities, including one zero-day under active attack (CVE-2022-26925) and two publicly known vulnerabilities (CVE-2022-29972 and CVE-2022-22713).

Vulnerabilities of particular note
First and foremost, we have CVE-2022-26925, an “important” spoofing vulnerability in Windows Local Security Authority (LSA) that may turn into a “critical” one if combined with NTLM relay attacks.
“Being actively exploited in the wild, this [vulnerability] allows an attacker to authenticate as approved users as part of an NTLM relay attack – letting threat actors gain access to the hashes of authentication protocols,” noted Kevin Breen, Director of Cyber Threat Research at Immersive Labs.
“While all servers are affected – domain controllers should be a priority for protection as, once exploited, this provides high level access to privileges, often known as ‘the keys to the kingdom.'”
The complexity of exploiting CVE-2022-26925 is considered high because exploitation requires an attacker to be positioned as an attacker-in-the-middle, added Satnam Narang, staff research engineer at Tenable, and joined Microsoft in urging administrators to patch this flaw, then follow it up with a review of two documents that delineate additional measures to mitigate NTLM relay attacks against Active Directory Certificate Services.
Next we have CVE-2022-29972, a flaw in a third-party ODBC data connector used to connect to Amazon Redshift in Azure Synapse pipelines and Azure Data Factory Integration Runtime.
Discovered and reported by Orca Security, the vulnerability “could have allowed an attacker to perform remote command execution across IR infrastructure not limited to a single tenant,” according to Microsoft, but was apparently not found and exploited by anyone else except Orca’s researchers.
Microsoft has, in fact, mitigated the vulnerability almost a month ago, and has shared a detailed blog post detailing its mitigation actions, as well as actions that some customers must take to implement the provided security updates so that attackers can’t leverage the flaw to exposes their organization’s confidential data.
Dustin Childs, with Trend Micro’s Zero Day Initiative, has singled out CVE-2022-26923, an EOP bug in Active Directory Domain Services, which may allow attackers to obtain a certificate that will allow them to authenticate to a domain controller with a high level of privilege – all they need is to include crafted data in a certificate request.
“In essence, any domain authenticated user can become a domain admin if Active Directory Certificate Services are running on the domain. This is a very common deployment. Considering the severity of this bug and the relative ease of exploit, it would not surprise me to see active attacks using this technique sooner rather than later,” he noted.
He also advised admins working with mixed Windows/Linux/Unix environments to quickly patch CVE-2022-26937, an unauthenticated RCE in the Windows Network File System (NFS) service.
Marked by Microsoft as ‘exploitation more likely,’ CVE-2022-26937 has the potential to be damaging, Breen added.
“These types of vulnerabilities will potentially appeal to ransomware operators as they could lead to the kind of exposure of critical data often part of a ransom attempt. It is also important for security teams to note that NFS Role is not a default configuration for Windows devices.”
UPDATE (May 12, 2022, 04:20 a.m. ET):
As it turns out, CVE-2022-26925 is not new:
To be clear CVE-2022-26925 is PetitPotam unauthenticated found by @topotam77 . MS reintroduced the vulnerability in some patch between Dec 2021 and March 2022
— Raphael (@raphajohnsec) May 10, 2022
The story behind CVE-2022-26925 is no advanced reverse engineering, but a lucky accident 😉
During my pentests in January and March i saw that PetitPotam worked against the DCs. 1/2— Raphael (@raphajohnsec) May 11, 2022
Also, there’s now more information about CVE-2022-26923, the Active Directory Domain Services EoP, by Oliver Lyak, who unearthed it.
It should definitely be prioritized for patching, but the patch should also be supplemented with additional actions.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/05/10/cve-2022-26925/