Null Pointer Dereference in Windows iSCSI Target Service by Microsoft
CVE-2026-65681

7.5HIGH

What is CVE-2026-65681?

A null pointer dereference vulnerability exists in Windows iSCSI Target Service, which can be exploited by unauthorized attackers to cause a denial of service. When the service processes certain inputs, it may lead to unexpected termination, impacting availability and functionality for users relying on this service over the network. It is crucial for administrators to apply recommended patches to mitigate this vulnerability and protect their systems from potential disruptions.

Affected Version(s)

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9418

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.9115

Windows Server 2016 (Server Core installation) x64-based Systems 10.0.14393.0 < 10.0.14393.9418

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.