Executive brief
A vulnerability exists in a core Windows component responsible for managing security policies and user authentication. An authorized user on the network could exploit this flaw to crash the system or make it unresponsive, leading to a denial of service. This could disrupt business operations by preventing users from logging in or accessing network resources.
Technical details
A denial of service vulnerability exists in the Windows Local Security Authority Subsystem Service (LSASS) due to uncontrolled resource consumption (CWE-400). An authenticated attacker with low privileges can trigger this vulnerability over the network without user interaction. Successful exploitation allows the attacker to exhaust system resources, leading to a crash or hang of the LSASS process, which typically forces a system reboot. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.
Affected products
- Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9339
- Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
- Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
- Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows Server 2012 6.2.9200.0 to 6.2.9200.26226
Timeline
- 2026-07-14: advisory: Initial publication by Microsoft and NVD