Denial of Service Vulnerability in Windows Local Session Manager by Microsoft
CVE-2025-26651

6.5MEDIUM

What is CVE-2025-26651?

A denial of service vulnerability exists in the Windows Local Session Manager, which could allow an authorized attacker to exploit exposed harmful functions. This could lead to a disruption in service, potentially affecting system availability over the network. Organizations should implement mitigations and ensure their systems are updated to mitigate risks associated with this vulnerability.

Affected Version(s)

Windows 11 version 22H2 ARM64-based Systems 10.0.22621.0 < 10.0.22621.5189

Windows 11 version 22H3 ARM64-based Systems 10.0.22631.0 < 10.0.22631.5189

Windows 11 Version 23H2 x64-based Systems 10.0.22631.0 < 10.0.22631.5189

References

EPSS Score

22% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.