Impact
Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network. This flaw is classified as CWE-125 and has the effect of causing a denial of service for affected systems.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server 2012, 2016, 2019, 2022, 2025. These affected products span both desktop and server operating systems with various architectures.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact. The EPSS score of < 1 % indicates a low probability of exploitation, and the vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation at the time of this analysis. The likely attack vector is network or local authentication traffic, as Kerberos is a network‑based protocol; based on the description, it is inferred that an attacker who can send crafted Kerberos requests may trigger the denial of service. exploitation attempts.
OpenCVE Enrichment