Security News > 2022 > May > Microsoft closes Windows LSA hole under active attack

Microsoft patched 74 security flaws in its May Patch Tuesday batch of updates.
At least one of the vulnerabilities disclosed is under active attack with public exploit code, according to Redmond, while two others are listed as having public exploit code.
The bug that's being exploited in the wild is a Windows LSA spoofing vulnerability tracked as CVE-2022-26925.
While the software giant classified the attack complexity as "High," it also noted that the vuln is under active attack.
The second publicly disclosed bug, CVE-2022-22713, is a denial-of-service vulnerability in Windows Hyper-V. Microsoft says exploitation of this one is less likely and requires an attacker to win a race condition.
"The only thing that prevents this vulnerability from being tagged with a higher CVSS is the fact that an attacker must entice a victim to log on to the administration UI using a browser and that the attack is highly complex," the researchers wrote.
News URL
https://go.theregister.com/feed/www.theregister.com/2022/05/11/microsoft_patch_tuesday/
Related news
- Microsoft patches Windows LSA spoofing zero-day under active attack (CVE-2022-26925) (source)
- Microsoft fixes new PetitPotam Windows NTLM Relay attack vector (source)
- Microsoft shares mitigation for Windows KrbRelayUp LPE attacks (source)
- Microsoft fixes under-attack Windows zero-day Follina (source)
- Microsoft: Windows 11 KB5012643 update will break some apps (source)
- Microsoft releases fixes for Azure flaw allowing RCE attacks (source)
- Microsoft fixes new NTLM relay zero-day in all Windows versions (source)
- Hackers have carried out over 65,000 attacks through Windows’ Print Spooler exploit (source)
- Microsoft fixes Windows Direct3D issue behind app crashes (source)
- Microsoft: Windows 10 20H2 has reached end of service (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-05-10 | CVE-2022-26925 | Authentication Bypass by Spoofing vulnerability in Microsoft products Windows LSA Spoofing Vulnerability. | 4.3 |
2022-05-10 | CVE-2022-22713 | Resource Exhaustion vulnerability in Microsoft Windows 10 and Windows Server Windows Hyper-V Denial of Service Vulnerability. | 1.9 |