Impact
Allocation of resources without limits or throttling in the Windows kernel enables an attacker to trigger a denial of service that can be initiated over the network. The weakness, identified as CWE‑770, arises when Remote Procedure Call (RPC) requests consume kernel resources until exhaustion, causing critical processes or the entire machine to become unresponsive. This impact compromises availability only and does not directly affect confidentiality or integrity.
Affected Systems
The affected platforms include Microsoft Windows 10 from version 1607 through 22H2, Windows 11 from build 23H2 through 26H1, and Windows Server from 2012 up to 2025, spanning both Server Core and standard installations. The vulnerability is present on x86, x64, and ARM64 architectures as delineated by the associated CPE strings.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, and the EPSS score of 1% suggests that some threat actors are actively targeting this flaw, although the exploitation probability remains relatively low. The attack vector is inferred to be network-based, with an unauthenticated attacker able to send crafted RPC traffic to the vulnerable system. Because it is not listed in the CISA KEV catalog, there is no documented widespread exploitation at the time of this analysis.
OpenCVE Enrichment