Impact
An uncaught exception in the Windows iSCSI Target Service can cause the service to stop, resulting in a denial of service that affects clients connected over the network. The vulnerability enables a user with appropriate privileges to disrupt availability of the iSCSI target without affecting data integrity.
Affected Systems
Microsoft Windows 10 (versions 1607 and 1809) and Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, including Server Core installations.
Risk and Exploitability
The vulnerability scores a moderate CVSS score of 6.5. The EPSS score is 1% and it is not listed in CISA’s KEV catalog. The likely attack vector requires an authorized user to trigger the unhandled exception over the network, suggesting that the risk is limited to environments where the iSCSI Target Service is enabled and exposed.
OpenCVE Enrichment