Impact
A heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute arbitrary code over the network. The flaw is identified as CWE-122, meaning that an attacker who gains execution in the context of lsasrv can potentially elevate privileges or compromise the entire system.
Affected Systems
The vulnerability affects a range of Microsoft operating systems, including Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; as well as several server editions such as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025.
Risk and Exploitability
With a CVSS score of 8.8, the flaw represents high severity. The EPSS score is less than 1%, indicating a relatively low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker who can reach the affected system with sufficient privileges can trigger the heap-based buffer overflow remotely, leading to full code execution on the host. The risk is amplified in environments where lsasrv interactions are frequent or where administrative rights are broadly distributed.
OpenCVE Enrichment