Impact
This vulnerability is an out‑of‑bounds read (CWE‑125) in the Windows Active Directory component. An attacker who already possesses authorized network access can trigger a crash or hang of the AD service, leading to a denial of service for users and applications that rely on directory functionality. The flaw has no known impact on confidentiality or integrity; its primary effect is to render the service unavailable.
Affected Systems
Microsoft Windows 10 Version 21H2 and 22H2 (32‑bit and 64‑bit), Microsoft Windows 11 Versions 24H2, 25H2, and 26H1 (ARM64 and 64‑bit as noted), and Microsoft Windows Server 2022 and Server 2025, including Server Core installations. These releases are impacted according to the vendor’s advisory.
Risk and Exploitability
With a CVSS score of 7.1 the issue is classified as medium severity. An EPSS score of less than 1% indicates that exploitation is unlikely at the current time. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread active exploitation. Because the flaw requires an attacker with already authorized privileges within the domain, the likely attack vector is an internal or compromised network user. Organizations should treat this as a medium‑severity risk that can be mitigated through patching and by limiting privileged account use.
OpenCVE Enrichment