According to Microsoft, the “ShadowCoerce” vulnerability previously disclosed as part of the June 2022 updates, which allowed attackers to target Windows servers in NTLM relay attacks, has now been patched.
See also: Microsoft: “Raspberry Robin” Windows worm detected on hundreds of networks

This NTLM relay attack method can be used by threat actors to force unpatched servers to authenticate against servers under the attacker, leading to a Windows domain takeover.
While no public announcement was made regarding this issue, the “MS-FSRVP PoC coercion exploit also known as “ShadowCoerce” was mitigated with CVE-2022-30154, which affected the same component.”
ACROS Security CEO Mitja Kolsekdiscovered that ShadowCoerce was silently patched while researching it with the 0Patch team for a micropatch release.
While it's good that Microsoft has patched this vulnerability ,it hasn't yet released details publicly and hasn't yet assigned a CVE ID.
This prompted security companies and researchers to ask Redmond for more transparency and to include more information about what is being fixed in its security bulletins.
ShadowCoerce was first discovered and analyzed by security researcher Lionel Gilles in late 2021, at the end of a presentation showcasing the PetitPotam.
See also: Microsoft Defender: Detecting vulnerabilities in Android/iOS devices on corporate networks

Fortunately, this attack method can only force authentication via MS-FSRVP (File Server Remote VSS Protocol) on systems where the File Server VSS Agent service is enabled.
MS-FSRVP is a remote procedure call (RPC)-based protocol used to create shadow copies of file shares on remote computers.
Unfortunately, as Gilles showed, this protocol is also vulnerable to attacks that allow threat actors to force (or coerce) a domain controller to authenticate against a malicious NTLM relay under their control.
The malicious server then relays or forwards the authentication request to a domain's Active Directory Certificate Services (AD CS) to obtain a TGT that allows the attacker to impersonate any network device, including a Windows.
After they impersonate a domain controller, they will gain elevated privileges that can be used to take over the Windows domain.
See also: Microsoft Teams for web just got new features
However, these types of attacks require a network to have already been compromised by a threat actor and relevant services to be running and accessible on a targeted server.
The best way to prevent such attacks is to follow Microsoft's advice on mitigating the PetitPotam NTLM relay attack.
