Learn about CVE-2020-1267, a denial of service vulnerability in the Local Security Authority Subsystem Service (LSASS) on various Windows systems. Find out about affected versions and mitigation steps.
This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused by a specially crafted authentication request.
Understanding CVE-2020-1267
This CVE addresses a denial of service vulnerability in the LSASS service.
What is CVE-2020-1267?
A denial of service vulnerability in LSASS is triggered by a crafted authentication request.
The Impact of CVE-2020-1267
The vulnerability can be exploited by an authenticated attacker, leading to a denial of service condition on affected systems.
Technical Details of CVE-2020-1267
This section covers the technical aspects of the CVE.
Vulnerability Description
Affected Systems and Versions
The following systems and versions are affected:
Exploitation Mechanism
The vulnerability is exploited when an authenticated attacker sends a specifically crafted authentication request to the LSASS service.
Mitigation and Prevention
Steps to address and prevent exploitation of CVE-2020-1267.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates
Microsoft has released a security update to fix the vulnerability in LSASS service.