Executive brief
A vulnerability exists in Windows Cryptographic Services, a core component that handles encryption and secure communications for the operating system. An unauthorized attacker could remotely trigger a memory leak, potentially leading to a denial-of-service condition where the system becomes unresponsive or crashes. This could disrupt business operations and the availability of services running on affected Windows and Windows Server machines.
Technical details
A memory leak vulnerability (CWE-401) exists in Windows Cryptographic Services due to the missing release of memory after its effective lifetime. The vulnerability is exploitable over the network by an unauthenticated attacker without user interaction. By repeatedly triggering the vulnerable code path, an attacker can exhaust system memory resources, leading to a denial-of-service (DoS) state. The issue affects multiple versions of Windows 10, Windows 11, and Windows Server 2012. Microsoft has released security updates to address this vulnerability.
Affected products
- Microsoft Windows 10 Version 1607 < 10.0.14393.9339
- Microsoft Windows 10 Version 1809 < 10.0.17763.9020
- Microsoft Windows 10 Version 21H2 < 10.0.19044.7548
- Microsoft Windows 10 Version 22H2 < 10.0.19045.7548
- Microsoft Windows 11 Version 24H2 < 10.0.26100.8875
- Microsoft, versions: Windows 11 Version 25H2 < 10.0.26200.8875
- Microsoft Windows 11 version 26H1 < 10.0.28000.2269
- Microsoft Windows Server 2012 < 6.2.9200.26226
Timeline
- 2026-07-14: advisory: Initial publication by Microsoft and NVD
- 2026-07-14: patched: Security updates released by Microsoft