QID 91803
Date Published: 2021-08-11
QID 91803: Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability August 2021
Microsoft releases the security update for Windows August 2021
The KB Articles associated with the update:
KB5005076
KB5005106
KB5005099
KB5005094
KB5005043
KB5005033
KB5005030
KB5005088
KB5005095
KB5005090
KB5005089
This QID checks for the file version of ntoskrnl.exe
The following versions of ntoskrnl.exe with their corresponding KBs are verified:
KB5005076
KB5005106
KB5005099
KB5005094
KB5005043
KB5005033
KB5005030
An unauthenticated attacker could call a method on the LSARPC interface and coerce the domain controller to authenticate against another server using NTLM
Solution
Vendor References
- KB5005030 -
support.microsoft.com/en-in/help/5005030 - KB5005033 -
support.microsoft.com/en-in/help/5005033 - KB5005043 -
support.microsoft.com/en-in/help/5005043 - KB5005076 -
support.microsoft.com/en-in/help/5005076 - KB5005088 -
support.microsoft.com/en-in/help/5005088 - KB5005089 -
support.microsoft.com/en-in/help/5005089 - KB5005090 -
support.microsoft.com/en-in/help/5005090 - KB5005094 -
support.microsoft.com/en-in/help/5005094 - KB5005095 -
support.microsoft.com/en-in/help/5005095 - KB5005099 -
support.microsoft.com/en-in/help/5005099 - KB5005106 -
support.microsoft.com/en-in/help/5005106
CVEs related to QID 91803
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| KB5005030 |
|
||
| KB5005033 |
|
||
| KB5005043 |
|
||
| KB5005076 |
|
||
| KB5005088 |
|
||
| KB5005089 |
|
||
| KB5005090 |
|
||
| KB5005094 |
|
||
| KB5005095 |
|
||
| KB5005099 |
|
||
| KB5005106 |
|