QID 91803

Date Published: 2021-08-11

QID 91803: Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability August 2021

Microsoft releases the security update for Windows August 2021

The KB Articles associated with the update:
KB5005076
KB5005106
KB5005099
KB5005094
KB5005043
KB5005033
KB5005030
KB5005088
KB5005095
KB5005090
KB5005089

This QID checks for the file version of ntoskrnl.exe

The following versions of ntoskrnl.exe with their corresponding KBs are verified:
KB5005076
KB5005106
KB5005099
KB5005094
KB5005043
KB5005033
KB5005030

An unauthenticated attacker could call a method on the LSARPC interface and coerce the domain controller to authenticate against another server using NTLM

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • CVEs related to QID 91803

    Software Advisories
    Advisory ID Software Component Link
    KB5005030 URL Logo support.microsoft.com/en-in/help/5005030
    KB5005033 URL Logo support.microsoft.com/en-in/help/5005033
    KB5005043 URL Logo support.microsoft.com/en-in/help/5005043
    KB5005076 URL Logo support.microsoft.com/en-in/help/5005076
    KB5005088 URL Logo support.microsoft.com/en-in/help/5005088
    KB5005089 URL Logo support.microsoft.com/en-in/help/5005089
    KB5005090 URL Logo support.microsoft.com/en-in/help/5005090
    KB5005094 URL Logo support.microsoft.com/en-in/help/5005094
    KB5005095 URL Logo support.microsoft.com/en-in/help/5005095
    KB5005099 URL Logo support.microsoft.com/en-in/help/5005099
    KB5005106 URL Logo support.microsoft.com/en-in/help/5005106

    © CVE.report 2026

    Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

    CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

    Free CVE JSON API cve.report/api

    CVE.report and Source URL Uptime Status status.cve.report