Junglewise Threat Intelligence

CVE-2026-42903: Microsoft Windows Kerberos null pointer dereference denial of service

CVE-2026-42903 · Severity: medium · CVSS 6.5 · Published 2026-06-09

Technologies: Microsoft Windows Kerberos. Vendors: Microsoft.

Executive brief

A vulnerability exists in the Windows Kerberos authentication service, which is used to verify user identities across a network. An authorized user could exploit this flaw to crash the service, leading to a denial of service. This could disrupt login processes and access to corporate resources, impacting business operations and availability.

Technical details

A NULL pointer dereference vulnerability (CWE-476) exists within the Microsoft Windows Kerberos implementation. The flaw is triggered when the service improperly handles specific malformed requests, leading to a process crash. An attacker must be authenticated (Low Privileges) to reach the vulnerable code path over the network. Successful exploitation results in a denial of service (DoS) of the Kerberos authentication functionality, though it does not allow for information disclosure or remote code execution. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows Kerberos

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats