Impact
This entry describes an out‑of‑bounds read vulnerability in the Windows iSCSI subsystem that permits an unauthorized attacker to trigger a denial of service across the network. The flaw is a classic memory boundary error (CWE‑125) that can lead to a crash of the iSCSI stack when it processes maliciously crafted iSCSI traffic. The resulting denial of service is limited to the affected host, but it disrupts connectivity for any clients communicating through that host.
Affected Systems
Affected systems include Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server 2012 (standard and core), Windows Server 2012 R2 (standard and core), Windows Server 2016, 2019, 2022, and 2025. All editions of these operating systems that contain the default iSCSI initiator component are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 signals a moderate severity. Because EPSS is not available, the current assessment of exploitation probability is uncertain, but the vulnerability requires only network connectivity to the host and thus could be abused by remote adversaries who can reach a target’s iSCSI port. The lack of a KEV listing indicates there are no known public exploits at this time, yet the nature of the flaw means that once a patch arrives, the risk of repeated denial attacks remains high.
OpenCVE Enrichment