CISA orders federal agencies to patch Windows bug
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-26925 | Spoofing Flaw in Windows LSA (CVE-2022-26925) Exploited Against Domain Controllers CVE-2022-26925 is a spoofing vulnerability in the Windows Local Security Authority (LSA) that lets an unauthenticated network attacker make a spoofed call to LSA on a remote Windows host. It is triggered over the network with no user interaction, typically by coercing a Windows system—most critically a domain controller—into authenticating via NTLM to an attacker-controlled machine, in the manner of the PetitPotam forced-authentication attacks referenced in CISA's catalog update. By spoofing the client when LSA processes that authentication, the attacker undermines NTLM's authentication guarantees and, when chained with relay techniques, can authenticate to a domain controller with elevated privileges, which is reflected in the CVSS high-integrity impact. Any organization running affected Windows clients or Windows Server versions is exposed, with domain controllers the highest-value targets. The flaw was exploited as a zero-day before Microsoft's June 2022 Patch Tuesday fixes and is now listed in CISA's Known Exploited Vulnerabilities catalog, with CISA ordering federal agencies to patch. Do: Apply Microsoft's June 2022 Patch Tuesday updates (per CISA's guidance for the June Microsoft patch, https://www.cisa.gov/guidance-applying-june-microsoft-patch) across all affected Windows versions, prioritizing domain controllers; systems that cannot yet patch should be protected with NTLM-related mitigations (e.g., enforced SMB signing, LDAP signing/channel binding, and restricting or auditing NTLM use) per CISA/Microsoft remediation guidance. Check whether domain controllers are internet-exposed or reachable from untrusted networks, and hunt for signs of forced-authentication/relay activity. Note that a related PetitPotam KEV entry was superseded, so ensure this newer LSA fix—not just the older PetitPotam patch—is deployed. | 5.9 | 11% | KEV |
| mass≈1 billion+ Windows installations worldwide (essentially every Windows environment, and domain controllers at virtually every Windows-running organization) |
Full article240 words · extracted from therecord.media · click to collapse
The Cybersecurity and Infrastructure Security Agency on Friday said that federal civilian executive branch agencies must apply remediations for a security bug affecting Microsoft devices by July 22. The vulnerability, tracked as CVE-2022-26925, was temporarily removed from CISA’s Known Exploited Vulnerability Catalog in May because of authentication failures associated with an update that was available at the time. The new guidance released by CISA includes steps to apply Microsoft’s June 2022 security updates — which address the vulnerability — without breaking certificate authentication or causing service outages. According to Microsoft, the bug is a Local Security Authority (LSA) spoofing vulnerability that could allow an unauthenticated hacker to “coerce the domain controller to authenticate to the attacker using NTLM” — the Windows New Technology LAN Manager security protocol — which could be used to take over the targeted Windows domain. The security update works by detecting and disallowing anonymous connection attempts. The updates are a fix to the PetitPotam security issue discovered by French researcher Gilles Lionel in 2021, which is particularly dangerous because it could allow attackers to take over large internal corporate networks. Security researchers at Google on Thursday highlighted CVE-2022-26925 as one of 18 0-days “detected and disclosed as exploited in-the-wild in 2022.” Although CISA’s Binding Operational Directive only applies to federal agencies, it has strongly recommended that businesses — as well as state, local, tribal and territorial government agencies — prioritize mitigations of these vulnerabilities as well.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-orders-federal-agencies-to-patch-windows-bug