Impact
The vulnerability is an out‑of‑bounds read in the Windows Kerberos implementation. An attacker who can send crafted Kerberos traffic can trigger the flaw, causing a denial of service on the affected systems. It is classified as CWE‑125.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2025, and Windows Server 2025 (Server Core installation). These affected products span both desktop and server operating systems across multiple architectures.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact. The EPSS score of < 1 % indicates a low probability of exploitation, and the vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation at the time of this analysis. The likely attack vector is network‑based Kerberos traffic, as Kerberos is a network‑based protocol; based on the description, it is inferred that an attacker who can send crafted Kerberos requests may trigger the denial of service.
OpenCVE Enrichment