Impact
The flaw is a null pointer dereference in Windows Active Directory Domain Services that can be triggered by legitimate service requests. An authorized attacker can cause the AD DS service to restart, resulting in a denial of service for domain users and clients that depend on authentication or directory services. The description does not mention exposure of confidential data or modification of system integrity; based on the wording we infer that the impact is limited to availability only.
Affected Systems
Affected devices include Microsoft Windows 10 starting with version 1607 up to 22H2, Windows 11 from 24H2 through 26H1, and Windows Server ranging from 2012 (including Core) through 2025 (including Core). The versions listed cover typical enterprise builds; any device running these operating systems that hosts AD DS is potentially impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is under 1%, suggesting a very low probability of exploitation in the wild. This vulnerability is not listed in CISA KEV, meaning no publicly catalogued active exploits are known. While the description does not specify the privilege level required, we infer that an attacker must possess sufficient rights to interact with AD DS (for example, a domain administrator or a compromised domain account). The attack vector is therefore likely internal or from an authenticated compromised account. Because the trigger is a normal service request, an authenticated attacker with these privileges can cause an inadvertent restart of the AD DS service, disrupting availability.
OpenCVE Enrichment