Junglewise Threat Intelligence

CVE-2026-20875: Microsoft Windows LSASS null pointer dereference denial of service

CVE-2026-20875 · Severity: high · CVSS 7.5 · Published 2026-01-13

Technologies: Microsoft Windows 10, Microsoft Windows Server 2008 R2, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A vulnerability exists in a core Windows component responsible for managing user logins and security policies. An unauthorized attacker can exploit this flaw over a network to crash the system service, leading to a complete loss of availability for the affected computer. This could disrupt business operations by forcing systems to restart or preventing users from logging in.

Technical details

A NULL pointer dereference vulnerability (CWE-476) exists within the Windows Local Security Authority Subsystem Service (LSASS). The flaw can be triggered by an unauthenticated attacker over the network without any user interaction. Successful exploitation causes the LSASS process to crash, which in turn triggers an immediate system reboot, resulting in a denial-of-service (DoS) condition. Microsoft has released security updates to address this issue across various versions of Windows 10, Windows 11, and Windows Server.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
  • Microsoft Windows Server 2008 R2 Service Pack 1

Timeline

  • 2026-01-13: disclosed
  • 2026-01-13: patched

References

Related threats