Impact
A null pointer dereference in the Windows Kerberos authentication stack allows an unauthorized network attacker to trigger a denial of service. The flaw causes the Kerberos service to crash, which prevents any user from authenticating via Kerberos on the affected host. The impact is limited to authentication failures and loss of service, but can be leveraged to disrupt operations for any user that relies on Kerberos tickets.
Affected Systems
Microsoft Windows 11 Version 24H2, Microsoft Windows 11 Version 25H2, Microsoft Windows Server 2025 and the Server Core installation of Windows Server 2025 are impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability. The EPSS score is 1%, and it is not listed in the CISA KEV catalog. The vulnerability can be exploited over the network by an attacker who can send crafted Kerberos traffic, giving any unauthenticated user the ability to cause the target service to crash. No special privileges are required beyond the ability to contact the Kerberos port.
OpenCVE Enrichment