Impact
The vulnerability involves a memory allocation bug in Windows Local Security Authority Subsystem Service (LSASS) where an excessive size value causes the process to crash or freeze. This leads to a denial of authentication and other security functions, resulting in a loss of availability for the system.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations; all affected versions are listed in the documented CNA vendor product list.
Risk and Exploitability
The CVSS score shows high severity (7.5), but the EPSS score of less than 1% indicates that exploitation is currently unlikely. The flaw can be triggered by an unauthorized attacker over a network connection, implying a remote attack vector. The vulnerability is not listed in the CISA KEV catalog, so there is no known widespread exploitation at the time of analysis.
OpenCVE Enrichment