Denial of Service Vulnerability in Microsoft Windows' Local Security Authority Subsystem
CVE-2025-53716

6.5MEDIUM

What is CVE-2025-53716?

A null pointer dereference issue has been identified in the Windows Local Security Authority Subsystem Service (LSASS) that could allow an authorized attacker to disrupt service through the network. This vulnerability poses a significant risk as it can be exploited to execute denial of service attacks, which may result in service unavailability.

Affected Version(s)

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.7678

Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.6216

Windows 10 Version 22H2 x64-based Systems 10.0.19045.0 < 10.0.19045.6216

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53716 : Denial of Service Vulnerability in Microsoft Windows' Local Security Authority Subsystem