Impact
The vulnerability is an untrusted pointer dereference in Windows Domain Controller components that can cause a denial of service when triggered by an unauthorized attacker. The flaw leads to a crash or hang of domain controller services, interrupting authentication, group membership, and other domain-wide functions and compromising the availability of critical network infrastructure without affecting confidentiality or integrity.
Affected Systems
The affected products are Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Microsoft Windows Server 2025 and its Server Core installation when configured as a Domain Controller. Any Domain Controller running those releases is vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, but the EPSS score of < 1% suggests that, at present, the likelihood of exploitation is very low. The vulnerability is not listed in CISA’s KEV catalog, and no workaround is provided. Based on the description, the likely attack vector is a network-based request that an attacker can send to a domain controller without prior authentication, resulting in a crash that disrupts domain services. The impact is limited to loss of availability for domain-dependent applications and services.
OpenCVE Enrichment