Impact
The vulnerability arises from using encryption mechanisms that do not provide sufficient strength in Windows Active Directory. The flaw allows an authorized attacker to bypass a security feature over a network.
Affected Systems
Affected user systems include Microsoft Windows 11 in the 23H2, 24H2, 25H2, and 26H1 release lines, as well as Microsoft Windows Server 2022 and Windows Server 2025 (including Server Core installations).
Risk and Exploitability
The CVSS score is 5.3. The EPSS score is less than 1%. The vulnerability is not listed in the KEV catalog. Based on the description, the flaw requires an authorized attacker and network communication to domain controllers.
OpenCVE Enrichment