Impact
Null pointer dereference in the Schannel TLS implementation in Microsoft Windows allows an authorized attacker to disrupt network services by causing the system to enter an unusable state. The flaw is classified as CWE-476 and is accessed over the network, leading to a denial of service for the targeted machine or, in some cases, the entire network segment if the affected system is a server. The impact is a loss of availability rather than confidentiality or integrity.
Affected Systems
Affected systems include Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1 (both ARM64 and x64 platforms), as well as Windows Server 2022 and Windows Server 2025 (including Server Core installations). All listed operating system releases are vulnerable unless patched by the latest Microsoft security update.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score is not available, suggesting that the exploit probability has not been quantified yet. The vulnerability is not listed in CISA KEV, so there is no evidence of widespread exploitation. Based on the description, the likely attack vector is a remote network connection that reaches the Schannel service, and an attacker who can authenticate or otherwise gain authorized access to the system may trigger a null‑reference fault, causing the service to terminate and the machine to become unresponsive.
OpenCVE Enrichment