Impact
The flaw is an authentication bypass that occurs through a capture‑and‑replay attack on Windows Kerberos, enabling an attacker who can capture a Kerberos authentication exchange to replay it and gain code execution on the target system. This bypass of authentication directly leads to remote code execution, exposing the confidentiality, integrity, and availability of data and services on the affected machine. The weakness is identified as CWE‑294, reflecting improper authentication handling.
Affected Systems
Affected are multiple Windows client and server families: Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025 (both regular and Server Core configurations). All listed operating system releases are impacted by this vulnerability.
Risk and Exploitability
The issue carries a CVSS score of 8.8, indicating high severity, and the EPSS score is 1%, but the lack of a KEV listing does not negate the risk. The attack likely requires an attacker to be able to capture network traffic containing a valid Kerberos ticket and then replay it; such conditions are typical for an authorized or opportunistic adversary on the same network. The resulting exploit enables arbitrary code execution, making the vulnerability critically significant for organizations running the affected Windows versions.
OpenCVE Enrichment