Impact
The vulnerability stems from weak authentication mechanisms in Windows iSCSI. An attacker who can communicate with the iSCSI service over a network can circumvent built‑in security controls. This bypass allows the attacker to gain elevated privileges on the target system, potentially leading to full system compromise. The weakness corresponds to CWE-1390, which describes insecure handling of authentication data.
Affected Systems
Affected operating systems include Microsoft Windows 10 version 1607 and 1809, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025. For each of these releases, both standard and Server Core installations are impacted. No specific patch level is indicated in the advisories, so all instances of these OS versions should be considered vulnerable until an update is applied.
Risk and Exploitability
The CVSS score of 9.8 classifies this as a critical vulnerability. While no EPSS value is provided, the lack of listed exploits in the KEV database does not diminish the risk; the weakness can be employed via the network without any local user interaction. The likely attack vector is a remote network connection to the iSCSI target, and the exploitation requires only that the attacker be able to reach the service. Organizations should assess whether iSCSI is in use and, if so, treat this as an available attack vector.
OpenCVE Enrichment