Executive brief
A vulnerability exists in a core Windows security component responsible for managing user logins and security policies. An unauthorized attacker can remotely crash this service, causing the affected computer to restart or become unresponsive. This can lead to a significant disruption of business operations and temporary loss of access to affected systems.
Technical details
This vulnerability is classified as a 'Memory Allocation with Excessive Size Value' (CWE-789) within the Windows Local Security Authority Subsystem Service (LSASS). An unauthenticated attacker can exploit this flaw over the network by sending a specially crafted request that triggers an oversized memory allocation. This leads to resource exhaustion or a service crash, resulting in a Denial of Service (DoS) condition. The vulnerability affects multiple versions of Windows 10 and Windows 11, and Microsoft has released security updates to address the issue.
Affected products
- Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9339
- Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
- Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
- Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
- Microsoft Windows 11 Version 23H2 10.0.22631.0 to 10.0.22631.7376
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
- Microsoft Windows 11 Version 26H1 10.0.28000.0 to 10.0.28000.2269
Timeline
- 2026-07-14: advisory: Microsoft published the vulnerability details and security updates.
- 2026-07-14: patched: Security updates released for affected Windows versions.