Local Security Authority Subsystem Service
{{Short description|Computer operating system component}}
{{Refimprove|date=July 2009}}
Local Security Authority Subsystem Service (LSASS){{cite web|url=https://docs.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection |title=Configuring Additional LSA Protection |publisher=Microsoft |access-date=2022-02-04}} is a process in Microsoft Windows operating systems that is responsible for enforcing the security policy on the system. It verifies users logging on to a Windows computer or server, handles password changes, and creates access tokens.{{cite web|url=https://ss64.com/nt/syntax-services.html |title=Windows 7 Services | Windows CMD |publisher=SS64.com |access-date=2016-05-24}} It also writes to the Windows Security Log.
Forcible termination of {{mono|lsass.exe}} will result in the system losing access to any account, including NT AUTHORITY, prompting a restart of the machine. Because, {{mono|lsass.exe}} is a crucial system file, its name is often faked by malware. The {{mono|lsass.exe}} file used by Windows is located in the directory {{mono|%WINDIR%\System32}}, and the description of the file is Local Security Authority Process. If it is running from any other location, that {{mono|lsass.exe}} is most likely a virus, spyware, trojan or worm. Due to the way some systems display fonts, malicious developers may name the file something like {{mono|Isass.exe}} (capital "i" instead of a lowercase "L") in efforts to trick users into installing or executing a malicious file instead of the trusted system file.{{cite web |url=http://www.errorboss.com/exe-files/lsass-exe/ |title=The Best Way To Remove Lsass.exe Virus - Fix Lsass Process |date=23 December 2014 |publisher=Errorboss.com |access-date=2016-05-24 |archive-date=2015-09-24 |archive-url=https://web.archive.org/web/20150924001856/http://www.errorboss.com/exe-files/lsass-exe/ |url-status=dead }} The Sasser worm spreads by exploiting a buffer overflow in the LSASS on Windows XP and Windows 2000 operating systems.
References
{{reflist}}
External links
- [https://technet.microsoft.com/en-us/library/cc961760.aspx Security Subsystem Architecture]
- [http://msdn.microsoft.com/en-us/library/windows/desktop/aa378326%28v=vs.85%29.aspx LSA Authentication]
- [http://www.microsoft.com/technet/security/topics/identitymanagement/idmanage/p2pass_1.mspx MS identity management]
{{Windows Components}}
Category:Microsoft Windows security technology
Category:Windows NT architecture