Impact
A null pointer dereference in the Windows TCP/IP stack can be triggered remotely over a network, causing the system to crash or become unresponsive. The flaw allows an attacker to cause a denial of service without needing privileged access. This vulnerability falls under CWE‑476, which signifies an attempt to dereference a null pointer.
Affected Systems
Microsoft Windows 11 24H2, Windows 11 25H2, Windows 11 26H1, Windows Server 2025, and the Server Core installation of Windows Server 2025. The affected builds include both ARM64 (for Windows 11 24H2 and 25H2) and x64 (for Windows 11 26H1) architectures.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity level for availability impact. The EPSS score is not available, but the lack of an entry in the CISA KEV catalog suggests no public exploitation has been confirmed. Attackers could exploit the vulnerability by sending crafted TCP/IP packets from a remote network, as the flaw does not require authentication. Successful exploitation would result in a service interruption for the affected host.
OpenCVE Enrichment