Impact
This vulnerability, identified as CWE‑400 (Resource Management Error), is an uncontrolled resource consumption issue in the Windows Local Security Authority Subsystem Service (LSASS). It allows an authorized attacker to consume sufficient system resources that the LSASS process becomes unresponsive, resulting in a denial‑of‑service for authentication and security services. The impact is a loss of availability of authentication and integrity verification functions on the affected system.
Affected Systems
Affected vendors include Microsoft. Vulnerable products are Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), and Windows Server (2012, 2012 R2, 2016, 2019, 2022, 2025), including both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, while the EPSS score of less than 1 % shows that exploitation is considered unlikely at present. The vulnerability is not listed in the CISA KEV catalog. An attacker must first obtain authorized access to the target system; local or compromised credentials are needed. Once authorized, the attacker can trigger the resource over‑consumption, leading to a denial of service for LSASS and, consequently, for authentication services across the network.
OpenCVE Enrichment