Executive brief
A vulnerability exists in the Windows Kerberos authentication protocol, which is the primary system used for verifying user identities in corporate networks. An attacker could exploit this flaw to cause a system crash or service interruption, effectively locking users out of the network or disrupting business operations. While the attack requires the perpetrator to have an existing low-level account on the network, it poses a significant risk to organizational availability.
Technical details
A denial of service vulnerability exists in the Microsoft Windows Kerberos implementation due to an out-of-bounds read (CWE-125). An authenticated attacker with low-level privileges can exploit this flaw over the network by sending specially crafted requests to a target system. Successful exploitation results in a crash of the Kerberos service or the host operating system, leading to a denial-of-service condition. The attack complexity is rated as high, suggesting specific timing or environmental conditions may be required for a successful exploit. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory