Impact
A null pointer dereference has been identified in the Microsoft Remote Registry Service. When triggered, the service processes a malformed request from an authorized remote client, causing the service to crash and stop responding to registry queries. This loss of the Remote Registry Service results in denial of service for any applications or administrators that rely on remote registry access. The weakness corresponds to CWE-476.
Affected Systems
The vulnerability affects multiple Microsoft Windows operating systems. Specifically, Windows 10 builds 1607, 1809, 21H2, and 22H2; Windows 11 builds 23H2, 24H2, 25H2, and 26H1; as well as Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core deployments.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. EPSS of 1% suggests that exploitation is unlikely but still possible. The attack requires an attacker to have legitimate network access and be able to communicate with the Remote Registry RPC endpoint, which is normally limited to authenticated users. Because the flaw leads only to a local denial of service for the Remote Registry Service, it does not directly expose data or allow further privilege escalation, but it can impact availability of management functions. The vulnerability is not yet listed in CISA’s KEV catalog. Organizations should assess whether the Remote Registry Service is critical to operations.
OpenCVE Enrichment