Impact
An infinite loop in Windows Active Directory prevents the service from processing requests, causing the server to become unresponsive to legitimate network traffic. The flaw is a classic example of CWE-835, where an improper loop termination condition leads to resource exhaustion and denial of service for affected clients.
Affected Systems
The vulnerability affects Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 24H2, 25H2, and 26H1; and Microsoft Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both full and Server Core installations.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, while the EPSS score of < 1% suggests a low current exploitation probability. The vulnerability is not yet listed in CISA’s KEV catalog. The likely attack vector is over the network to an Active Directory service, as the affected component processes remote requests; based on the description, it is inferred that any client able to communicate with the AD server could trigger the denial of service.
OpenCVE Enrichment