Microsoft Windows NTLM Spoofing Vulnerability Allowing Unauthorized Network-Based Attacks

Vulnerability

A vulnerability in Windows NTLM allows unauthorized attackers to perform spoofing attacks over the network by externally controlling file names or paths. This issue affects multiple Windows Server and Windows 10 versions, as well as Windows 11 and Windows Server 2025.

Impact

Exploitation of this vulnerability could lead to unauthorized spoofing over the network.

Remediation

Users can apply the security update for this vulnerability, which is available through the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base articles linked in the 'Security Update Guide'.

Added: Jan 13, 2026, 7:37 PM
Updated: Jan 13, 2026, 7:37 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
1.3
exploitability
4.4
remediation
7.7
relevance
2.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.