Impact
The vulnerability targets the Windows TCP/IP stack, resulting in a denial of service that interrupts network communication on the affected machine. The issue can bring a system offline until a restart or update restores the networking component.
Affected Systems
Affected Windows products include Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server releases from Server 2012 through Server 2025, including standard and Server Core installations.
Risk and Exploitability
The CVSS score is 7.1, indicating a high‑medium severity for denial of service. The EPSS score is <1%, suggesting a very low, but non‑zero, probability of exploitation; the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the attack may require local access, although remote exploitation is not documented.
OpenCVE Enrichment