#VU62921 Man-in-the-Middle (MitM) attack in Windows and Windows Server - CVE-2022-26925
Published: May 10, 2022
Windows
Windows Server
Microsoft
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists within the Windows LSA service. A remote attacker can call a method on the LSARPC interface and coerce the domain controller to authenticate to the attacker using NTLM. As a result, an attacker can obtain credentials and compromise the affected system via the NTLM Relay Attack.
Note, the vulnerability is being actively exploited in the wild.