CVE-2021-36942
Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability
Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to authenticate against another server using NTLM.
Actief misbruikt. Toegevoegd aan de CISA KEV-catalogus op 3 nov. Vereiste actie: Apply updates per vendor instructions. Bekend gebruik in ransomwarecampagnes.