Impact
Improper certificate validation in Windows Cryptographic Services enables an unauthorized attacker to bypass a security feature over a network. This flaw is classified as CWE‑295 and could allow attackers to present forged or otherwise invalid certificates to the operating system, potentially leading to impersonation or man‑in‑the‑middle attacks against services that rely on certificate validation. The impact is an authentication bypass that undermines the integrity of secure communications.
Affected Systems
Affected systems include Microsoft Windows 10 21H2 and 22H2, Windows 11 24H2, 25H2, and 26H1, as well as Windows Server 2022 and Windows Server 2025 (including Server Core installations). All versions listed in the vendor’s advisory are impacted, and no newer versions were reported as unused.
Risk and Exploitability
The CVSS score of 4.2 indicates a low to moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, further indicating limited current exploitation activity. Attack vectors are likely network‑based, requiring an attacker to deliver a crafted certificate or establish a connection that exploits the validation bypass. Overall risk remains modest, but the flaw remains actionable and should be remediated promptly when updates are available.
OpenCVE Enrichment