Impact
The vulnerability, classified as CWE-125 out‑of‑bounds read in Windows Kerberos, allows an attacker to send a crafted request over the network and cause the Kerberos service to crash, thereby denying authentication and other Kerberos‑dependent services. This flaw can disrupt user log‑ins and other services that rely on Kerberos tickets, impacting availability.
Affected Systems
Microsoft Windows 10 releases 1607, 1809, 21H2, 22H2; Windows 11 releases 23H2, 24H2, 25H2, 26H1; Windows Server 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 7.5 highlights a high impact and medium to high exploitability. EPSS score of 1% and the vulnerability is not yet listed on the CISA KEV catalog, suggesting no known widespread exploitation yet. The attack requires the ability to send network traffic to a target system’s Kerberos service; it can be executed over a standard network without requiring local privileges, making it a potentially remote denial‑of‑service vector.
OpenCVE Enrichment