Home
LOW: 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C 10.0.14393.0 (custom) before 10.0.14393.8868
affected
10.0.17763.0 (custom) before 10.0.17763.8389
affected
10.0.19044.0 (custom) before 10.0.19044.6937
affected
10.0.19045.0 (custom) before 10.0.19045.6937
affected
10.0.22631.0 (custom) before 10.0.22631.6649
affected
10.0.22631.0 (custom) before 10.0.22631.6649
affected
10.0.26100.0 (custom) before 10.0.26100.7840
affected
10.0.26200.0 (custom) before 10.0.26200.7840
affected
10.0.28000.0 (custom) before 10.0.28000.1575
affected
10.0.28000.0 (custom) before 10.0.28000.1575
affected
6.3.9600.0 (custom) before 6.3.9600.23022
affected
6.3.9600.0 (custom) before 6.3.9600.23022
affected
10.0.14393.0 (custom) before 10.0.14393.8868
affected
10.0.14393.0 (custom) before 10.0.14393.8868
affected
10.0.17763.0 (custom) before 10.0.17763.8389
affected
10.0.17763.0 (custom) before 10.0.17763.8389
affected
10.0.20348.0 (custom) before 10.0.20348.4773
affected
10.0.25398.0 (custom) before 10.0.25398.2149
affected
10.0.26100.0 (custom) before 10.0.26100.32370
affected
10.0.26100.0 (custom) before 10.0.26100.32370
affected
Description
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
Problem types
CWE-73: External Control of File Name or Path
Product status
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21249 (Windows NTLM Spoofing Vulnerability)