6.5
CVE-2025-53809
- EPSS 0.48%
- Veröffentlicht 09.09.2025 17:01:16
- Zuletzt bearbeitet 22.09.2025 17:12:18
- Quelle secure@microsoft.com
- CVE-Watchlists
- Unerledigt
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 11 24h2 Version < 10.0.26100.6508
Microsoft ≫ Windows Server 2025 Version < 10.0.26100.6508
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.48% | 0.652 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| secure@microsoft.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.