Denial of Service Vulnerability in Microsoft Windows Local Security Authority Subsystem Service
CVE-2025-53809

6.5MEDIUM

What is CVE-2025-53809?

The vulnerability in the Windows Local Security Authority Subsystem Service (LSASS) arises from improper input validation, enabling an authorized attacker to execute a denial-of-service attack over the network. This flaw can disrupt service availability, exposing systems to potential threats and unauthorized access. It is crucial for organizations to apply necessary updates and mitigate risks associated with this vulnerability to enhance overall security posture.

Affected Version(s)

Windows 11 Version 24H2 ARM64-based Systems 10.0.26100.0 < 10.0.26100.6584

Windows Server 2025 (Server Core installation) x64-based Systems 10.0.26100.0 < 10.0.26100.6584

Windows Server 2025 x64-based Systems 10.0.26100.0 < 10.0.26100.6584

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53809 : Denial of Service Vulnerability in Microsoft Windows Local Security Authority Subsystem Service