Executive brief
Windows Kerberos is the authentication system used to verify user identity in corporate networks. A null pointer dereference vulnerability allows an unauthenticated attacker to crash the authentication service over the network, causing users to be unable to log in or access network resources until the service is restarted.
Technical details
A null pointer dereference vulnerability exists in the Windows Kerberos authentication subsystem, allowing an unauthenticated attacker to send specially crafted network packets that cause the service to crash. The vulnerability is triggered through the network without requiring authentication or user interaction. Successful exploitation results in denial of service against the Kerberos service, disrupting authentication for domain-joined systems. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed