Impact
The vulnerability is a null pointer dereference in Active Directory Domain Services (AD DS), identified as CWE‑476. An attacker with some level of domain access can send a crafted packet to a domain controller, causing the AD DS process to crash. The crash disables AD DS, which is critical for authentication, authorization, and directory lookups, resulting in a denial of service for all services dependent on domain controllers.
Affected Systems
Affected are Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 24H2, 25H2, 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, 2025, including standard and Server Core installations.
Risk and Exploitability
The CVSS score of 6.5 denotes moderate severity. The EPSS score of less than 1 % indicates exceptional infrequency of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a network‑based request sent to a domain controller, as the error occurs while parsing network traffic. The attacker must have some level of domain access to inject the malformed request.
OpenCVE Enrichment