CVE Radar

CVE Radar Logo
CVERadar

Edition used by more than 30,000 companies in more than 150 countries.
Sign Up For Free

CVE-2022-26925

High Severity|Microsoft
62
SVRS
5.9
CVSSv3
0.37425
EPSS
TAGS
In The WildExploit In The WildExploit AvaliableCISA KEV
VECTOR STRING
CVSS:3.1AV:NAC:HPR:NUI:NS:UC:NI:HA:N
PUBLICATION DATE2022-05-10
LAST MODIFIED2025-10-21

Deep CVE Analysis in Progress

The system is currently conducting an in-depth analysis of the selected CVE. This includes advanced correlation, vulnerability classification, and cross-referencing with real-time threat intelligence sources. Once the analysis is complete, the page will automatically update with enriched vulnerability data and actionable insights.

Security Intelligence Brief

1. What is this vulnerability and why does it matter?
This vulnerability, identified as CVE-2022-26925, is a Windows LSA Spoofing Vulnerability. It matters significantly because it allows an attacker to bypass authentication mechanisms or impersonate legitimate entities within the Local Security Authority (LSA) of a Windows system. The existence of active exploits for this vulnerability indicates that it is a known and potentially weaponized threat, posing an immediate risk for unauthorized access or privilege escalation on affected systems.
2. What are the CVSS score, severity level, and disclosure details?
The CVSS score for this vulnerability is 5.9. Based on the CVSS v3 scoring system, this places the severity level as Medium. The vulnerability was publicly disclosed and published on 2022-05-10 20:33:41 UTC. The CVE record was last modified on 2025-10-21 23:15:39 UTC.
3. Which products, vendors, systems, and versions are affected?
This vulnerability affects the Local Security Authority (LSA) component within Microsoft Windows operating systems. The vendor is Microsoft. Specific affected versions of Windows are not detailed in the provided CVE data, but it is broadly described as a "Windows LSA Spoofing Vulnerability."
4. What is the technical root cause and attack vector?
The technical root cause is categorized under CWE-306, which represents a "Missing Authentication for Critical Function." This indicates that a critical security function within the Windows LSA does not properly enforce authentication, allowing an attacker to bypass or circumvent necessary checks. The attack vector involves spoofing, where an attacker likely impersonates a legitimate user, service, or system component to gain unauthorized access or perform privileged actions. The presence of active exploits suggests the attack vector is well-defined and potentially easy to leverage.
5. How can this vulnerability be exploited?
This vulnerability can be exploited by an attacker leveraging the missing authentication flaw within the Windows LSA to spoof or impersonate a legitimate entity. This could allow the attacker to bypass security controls or gain unauthorized access to resources or elevated privileges. The CVE data explicitly states that active exploits have been published, confirming that mechanisms for exploitation are publicly available and potentially being used in the wild.
10. What public intelligence references and advisories exist?
The primary public intelligence reference is the CVE identifier itself: CVE-2022-26925. The fact that "active exploits have been published to exploit the vulnerability" serves as an advisory indicating the immediate and ongoing threat posed by this flaw, urging administrators to address it.
11. What is the risk assessment and urgency level?
The risk assessment for CVE-2022-26925 is significant. While the CVSS score of 5.9 places it in the Medium severity range, the presence of active exploits drastically increases the practical risk. A spoofing vulnerability affecting a critical component like Windows LSA can lead to severe consequences, including unauthorized access, privilege escalation, and compromise of system integrity. The urgency level is High, primarily due to the confirmed existence of active exploits, which means systems are immediately susceptible to attack. Organizations should prioritize patching or mitigation efforts to protect against this actively exploited vulnerability.
TypeIndicatorDate
IP
116.55.229.2342020-08-26Search on IOC Radar
TitleSoftware LinkDate
Microsoft Windows LSA Spoofing Vulnerabilityhttps://www.cisa.gov/search?g=CVE-2022-269252022-07-01
Windows LSA Spoofing Vulnerability....https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-269252022-05-28
Ostorlab/KEVhttps://github.com/Ostorlab/KEV2022-04-19
Ostorlab/known_exploited_vulnerbilities_detectorshttps://github.com/Ostorlab/known_exploited_vulnerbilities_detectors2022-04-19
SOCRadar Logo

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence

Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.

CREATE FREE ACCOUNT
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

No news found for this CVE

No tweets found for this CVE

Configuration 1
TypeVendorProduct
OSMicrosoftwindows_server_2008
OSMicrosoftwindows_10
OSMicrosoftwindows_8.1
OSMicrosoftwindows_11
OSMicrosoftwindows_server_2016
OSMicrosoftwindows_server_2012
OSMicrosoftwindows_server_2019
OSMicrosoftwindows_7
OSMicrosoftwindows_rt_8.1
OSMicrosoftwindows_server
OSMicrosoftwindows_10_1809
OSMicrosoftwindows_10_1507
OSMicrosoftwindows_10_1607
OSMicrosoftwindows_10_1909
OSMicrosoftwindows_10_20h2
OSMicrosoftwindows_server_2022
OSMicrosoftwindows_10_21h2
OSMicrosoftwindows_10_21h1
OSMicrosoftwindows_11_21h2
OSMicrosoftwindows_server_20h2
ReferenceLink
AF854A3A-2127-422B-91AE-364DA2661108https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-26925
[email protected]https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26925
WINDOWS LSA SPOOFING VULNERABILITYhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26925
MISChttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-26925
MISChttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-26925
INTHEWILDhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26925
INTHEWILDhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-26925
INTHEWILDhttps://nvd.nist.gov/vuln/detail/CVE-2022-26925
INTHEWILDhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26925
INTHEWILDhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-26925
INTHEWILDhttps://nvd.nist.gov/vuln/detail/CVE-2022-26925
INTHEWILDhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26925
INTHEWILDhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26925
INTHEWILDhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-26925
[email protected]https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-26925
AF854A3A-2127-422B-91AE-364DA2661108https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-26925
[email protected]https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26925
WINDOWS LSA SPOOFING VULNERABILITYhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26925
WINDOWS LSA SPOOFING VULNERABILITYhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26925
[email protected]https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26925
CWE IDCWE NameDescription
CWE-306Missing Authentication for Critical FunctionThe software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.