{"cvss":7.5,"datePublished":"2021-11-03","dateUpdated":"2021-11-03","description":"Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to authenticate against another server using NTLM.","dueDate":"2021-11-17","id":"CVE-2021-36942","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Known","notes":"https://nvd.nist.gov/vuln/detail/CVE-2021-36942","product":"Windows","requiredAction":"Apply updates per vendor instructions.","severity":"HIGH","source":"cisa_known_exploited","title":"Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability","vendor":"Microsoft"}