ZeroHour
The Recordpublished ()ingested

CISA removes 'PetitPotam' bug from catalog after Microsoft warns of risk to domain controllers

criticalRansomware exploited in the wildimportance 60CVE-2022-26925CVE-2021-36942

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-36942
Unauthenticated LSA Spoofing (PetitPotam NTLM Relay) in Microsoft Windows

CVE-2021-36942 is a spoofing flaw in the Windows Local Security Authority (LSA), widely known as "PetitPotam," that lets an unauthenticated network attacker trick a Windows host into authenticating with NTLM to a machine the attacker controls. It is triggered remotely with no privileges and no user interaction (CVSS 3.1 AV:N/AC:L/PR:N/UI:N) by sending crafted requests that coerce the target system to authenticate. By relaying that coerced authentication to other services, an attacker can impersonate the machine — most critically a domain controller — and escalate toward domain-administrator access, producing a high confidentiality impact. All listed Windows Server releases are affected, with domain controllers and certificate-services servers as the highest-value targets. The flaw is actively exploited in the wild: it was added to CISA's KEV on 2021-11-03 with known ransomware use (LockFile and Babuk campaigns chained it with Exchange flaws), and Microsoft has released Windows updates to address it.

Do: Apply Microsoft's Windows updates per vendor instructions, prioritizing domain controllers and servers running Active Directory Certificate Services. As interim hardening, require SMB signing and restrict NTLM authentication per Microsoft guidance, and review authentication logs for unexpected NTLM connections from domain controllers to certificate-services endpoints.

7.566% KEV ransomware PoC
  • Microsoft Windows (per CISA affected listing) as listed by CISA
  • Microsoft Windows Server 2004 as listed in CISA/CPE data
  • Microsoft Windows Server 2008 as listed in CISA/CPE data
  • +4 more
massmillions of Windows Server deployments; hundreds of thousands of SMB-exposed hosts in public internet scans
CVE-2022-26925
Spoofing Flaw in Windows LSA (CVE-2022-26925) Exploited Against Domain Controllers

CVE-2022-26925 is a spoofing vulnerability in the Windows Local Security Authority (LSA) that lets an unauthenticated network attacker make a spoofed call to LSA on a remote Windows host. It is triggered over the network with no user interaction, typically by coercing a Windows system—most critically a domain controller—into authenticating via NTLM to an attacker-controlled machine, in the manner of the PetitPotam forced-authentication attacks referenced in CISA's catalog update. By spoofing the client when LSA processes that authentication, the attacker undermines NTLM's authentication guarantees and, when chained with relay techniques, can authenticate to a domain controller with elevated privileges, which is reflected in the CVSS high-integrity impact. Any organization running affected Windows clients or Windows Server versions is exposed, with domain controllers the highest-value targets. The flaw was exploited as a zero-day before Microsoft's June 2022 Patch Tuesday fixes and is now listed in CISA's Known Exploited Vulnerabilities catalog, with CISA ordering federal agencies to patch.

Do: Apply Microsoft's June 2022 Patch Tuesday updates (per CISA's guidance for the June Microsoft patch, https://www.cisa.gov/guidance-applying-june-microsoft-patch) across all affected Windows versions, prioritizing domain controllers; systems that cannot yet patch should be protected with NTLM-related mitigations (e.g., enforced SMB signing, LDAP signing/channel binding, and restricting or auditing NTLM use) per CISA/Microsoft remediation guidance. Check whether domain controllers are internet-exposed or reachable from untrusted networks, and hunt for signs of forced-authentication/relay activity. Note that a related PetitPotam KEV entry was superseded, so ensure this newer LSA fix—not just the older PetitPotam patch—is deployed.

5.911% KEV
  • microsoft windows 10 1507, 1607, 1809, 1909, 20H2, 21H1, 21H2
  • microsoft windows 11 21H2
  • microsoft windows 7
  • +3 more
mass≈1 billion+ Windows installations worldwide (essentially every Windows environment, and domain controllers at virtually every Windows-running organization)
Full article841 words · extracted from therecord.media · click to collapse

The Cybersecurity and Infrastructure Security Agency (CISA) removed a Microsoft vulnerability from its catalog of known exploited bugs after the company reported issues with how an update addressing the issue affected domain controllers. 

[Here's what's missing: We don't explain what removal would mean. The bug still exists and is being exploited, right? So what does it mean to take it off the list if those things are still happening? Like, the logic is "Here is a list of diseases that kill people. We are removing one of the diseases from the list." In that case, you'd assume the disease is no longer killing people, or has been totally eradicated, right? That's really the interesting thing here: The politics of it. ]

A domain controller is a type of computer server that responds to security authentication requests and verifies users on the domain of a computer network.

CVE-2022-26925 — a vulnerability included in Microsoft’s Patch Tuesday release last week — is a Windows Local Security Authority (LSA) Spoofing vulnerability that was publicly disclosed and is being exploited in the wild, according to Microsoft. 

Allan Liska, senior security architect at Recorded Future, said the vulnerability should be a priority for those in charge of patching systems.

“This vulnerability impacts Windows 7 through 10 and Windows Server 2008 through 2022. Microsoft has rated this vulnerability as important and assigned it a CVSS score of 8.1, though Microsoft notes that the CVSS score can be as high as 9.8 in certain situations,” Liska explained last week. 

“Microsoft patched a similar vulnerability, CVE-2021-36942, in August of last year which was also being exploited in the wild under the name PetitPotam. CVE-2021-36942 was so bad it made CISA’s catalog of Known Exploited Vulnerabilities.”

But on Friday, CISA said it was contacted by Microsoft and told to temporarily remove the vulnerability from its list “due to a risk of authentication failures when the May 10, 2022 Microsoft rollup update is applied to domain controllers.”

“After installing May 10, 2022 rollup update on domain controllers, organizations might experience authentication failures on the server or client for services, such as Network Policy Server (NPS), Routing and Remote access Service (RRAS), Radius, Extensible Authentication Protocol (EAP), and Protected Extensible Authentication Protocol (PEAP). Microsoft notified CISA of this issue, which is related to how the mapping of certificates to machine accounts is being handled by the domain controller,” CISA explained. 

“Installation of updates released May 10, 2022, on client Windows devices and non-domain controller Windows Servers will not cause this issue and is still strongly encouraged. This issue only affects May 10, 2022 updates installed on servers used as domain controllers.”

Experts noted that it is rare for CISA to remove a vulnerability from its Known Exploited Vulnerabilities Catalog but said it has happened before. 

Bugcrowd CTO Casey Ellis told The Record that CISA made the right decision because there is always a risk that there will be unexpected consequences when vendors provide updates, especially if they're released under duress from active exploitation.

“Because the potential for a breach using CVE-2022-26925 may be more disruptive to an organization than the possibility for a breach using that vulnerability, CISA has reverted to advocating proper testing before patch release,” Ellis said. 

“This type of testing is routine procedure, but it's easy to skip through while a vulnerability is actively exploited. CISA has moved the conversation from vulnerability to risk, and signaled to the market that this is the approach they are adopting to these recommendations by granting a temporary removal.”

Viakoo CEO Bud Broomhead said it is surprising things like this don’t happen more often considering how many companies are forced to rush out updates due to the urgency caused by exploitation. 

Very likely there will soon be a patch that remediates this vulnerability across all Windows instances,” Broomhead said. 

“This should not take away the urgency behind applying security fixes as quickly as possible after it is available.” 

Microsoft released additional guidance for those dealing with the specific situation explained by CISA. 

CVE-2021-36942 relates back to the PetitPotam” vulnerability discovered by French researchers that Microsoft said it fixed last year. 

Multiple researchers revealed that Microsoft had not actually fixed the vulnerability and several ransomware groups have been seen exploiting it.

Raphael John, who is credited by Microsoft with discovering it, said it was a mistake on Microsoft’s part. 

At the first occurrence I thought that they did not updated their DCs but at the second pentest I knew that the DCs were up to date. After that I analysed that strange behaviour and concluded that MS made a big mistake in one of their updates. 2/2

— Raphael (@raphajohnsec) May 11, 2022

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-removes-petitpotam-bug