Home
MEDIUM: 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C 10.0.14393.0 (custom) before 10.0.14393.8783
affected
10.0.17763.0 (custom) before 10.0.17763.8276
affected
10.0.19044.0 (custom) before 10.0.19044.6809
affected
10.0.19045.0 (custom) before 10.0.19045.6809
affected
10.0.22631.0 (custom) before 10.0.22631.6491
affected
10.0.22631.0 (custom) before 10.0.22631.6491
affected
10.0.26100.0 (custom) before 10.0.26100.7623
affected
10.0.26200.0 (custom) before 10.0.26200.7623
affected
6.1.7601.0 (custom) before 6.1.7601.28117
affected
6.1.7601.0 (custom) before 6.1.7601.28117
affected
6.0.6003.0 (custom) before 6.0.6003.23717
affected
6.0.6003.0 (custom) before 6.0.6003.23717
affected
6.2.9200.0 (custom) before 6.2.9200.25868
affected
6.2.9200.0 (custom) before 6.2.9200.25868
affected
6.3.9600.0 (custom) before 6.3.9600.22968
affected
6.3.9600.0 (custom) before 6.3.9600.22968
affected
10.0.14393.0 (custom) before 10.0.14393.8783
affected
10.0.14393.0 (custom) before 10.0.14393.8783
affected
10.0.17763.0 (custom) before 10.0.17763.8276
affected
10.0.17763.0 (custom) before 10.0.17763.8276
affected
10.0.20348.0 (custom) before 10.0.20348.4648
affected
10.0.25398.0 (custom) before 10.0.25398.2092
affected
10.0.26100.0 (custom) before 10.0.26100.32230
affected
10.0.26100.0 (custom) before 10.0.26100.32230
affected
Description
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
Problem types
CWE-73: External Control of File Name or Path
Product status
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20925 (NTLM Hash Disclosure Spoofing Vulnerability)