Impact
A stack‑based buffer overflow in the Windows Netlogon service allows an attacker who is not authenticated to execute arbitrary code on the target server over the network.
Affected Systems
Microsoft Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022 (including the 23H2 edition), and Windows Server 2025, including their Server Core installations on 64‑bit builds. Specific version numbers are not listed in the vulnerability advisory; only the vendor and product names are provided.
Risk and Exploitability
The CVSS base score of 9.8 classifies the vulnerability as critical, and the EPSS value of <1% indicates that the likelihood of active exploitation is very low. It is not listed in the CISA KEV catalog. Attackers must be able to reach the vulnerable Netlogon service on the target server; once the stack overflow is triggered, arbitrary code execution is possible. The combination of a critical severity score and a very low exploitation probability underscores the need for rapid remediation.
OpenCVE Enrichment