Impact
A null pointer dereference occurs in the Windows iSCSI Target Service when it parses certain iSCSI traffic, causing the service to crash. This flaw enables an unauthenticated network attacker to disrupt the service, leading to a loss of availability for any workloads or devices that depend on the iSCSI target. The vulnerability does not provide code execution, data disclosure, or privilege escalation, and is therefore classified as a pure denial‑of‑service condition.
Affected Systems
Windows 10 versions 1607 and 1809, and Windows Server releases 2016, 2019, 2022, and 2025—including their Server Core editions—are affected. The flaw resides in the native iSCSI target stack shipped with these operating systems.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is over the network via unauthorized iSCSI traffic; a remote attacker with network access to the host can trigger the crash without requiring local privileges.
OpenCVE Enrichment