Impact
The vulnerability allows an attacker to trigger service crashes in the Kerberos authentication service, causing temporary denial of service for legitimate users. It is a memory corruption flaw classified as CWE-125, which can lead to instability of the affected Windows systems without providing an attacker with direct access to data or execution capabilities. The impact is limited to service availability and may affect network authentication for domain-connected devices.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025. These affected products span both desktop and server operating systems with various architectures as indicated by the CPE list.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact. No EPSS score is available, and the vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation at the time of this analysis. The likely attack vector is network or local authentication traffic, as Kerberos is a network-based protocol; based on the description, it is inferred that an attacker who can send crafted Kerberos requests may trigger the denial of service. Logging of authentication failures would be a sign of exploitation attempts.
OpenCVE Enrichment