Security News > 2022 > May > New Windows PetitPotam NTLM Relay attack vector fixed in May updates
A recent security update for a Windows NTLM Relay Attack has been confirmed to be a previously unfixed vector for the PetitPotam attack.
PetitPotam is an NTLM Relay Attack tracked as CVE-2021-36942 that French security researcher GILLES Lionel discovered, aka Topotam, in July.
BleepingComputer has since confirmed that the recently fixed NTLM Relay Attack bug does fix an unpatched vector for the PetitPotam attack.
Raphael John, who Microsoft attributes for the discovery of the new NTLM Relay vulnerability, says that he discovered that PetitPotam was still working when conducting pentests in January and March.
Gilles has confirmed to BleepingComputer that the new security update has now fixed the PetitPotam 'EfsRpcOpenFileRaw' vector, but other EFS vectors still exist, allowing the attack to work.
As new PetitPotam vectors and other NTML Relay attacks will be discovered in the future, Microsoft suggests that Windows domain admins become familiar with the mitigations outlined in their 'Mitigating NTLM Relay Attacks on Active Directory Certificate Services' support document.
News URL
Related news
- Exploit released for new Windows Server "WinReg" NTLM Relay attack (source)
- JPCERT shares Windows Event Log tips to detect ransomware attacks (source)
- Windows Themes zero-day bug exposes users to NTLM credential theft (source)
- Windows infected with backdoored Linux VMs in new phishing attacks (source)
- Microsoft patches Windows zero-day exploited in attacks on Ukraine (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-08-12 | CVE-2021-36942 | Unspecified vulnerability in Microsoft products Windows LSA Spoofing Vulnerability | 7.5 |