Impact
The vulnerability exists in Windows Schannel where the cryptographic signature of a certificate is not properly verified. This flaw permits an attacker to forge or supply an invalid signed certificate that bypasses a security feature during a network connection, reducing the integrity guarantees that Schannel is expected to provide. The weakness is classified as CWE‑347, representing failure to verify a cryptographic signature.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. Although the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, the issue can be exploited over a network by an unauthenticated attacker who can present a forged certificate. No code execution or privilege escalation is described, but the attacker can bypass the intended security mechanism of Schannel.
OpenCVE Enrichment