Home
Description
Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.
PUBLISHED Reserved 2025-07-09 | Published 2025-08-12 | Updated 2025-09-17 | Assigner microsoft
MEDIUM: 6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
Problem types
CWE-476: NULL Pointer Dereference
Product status
10.0.17763.0 before 10.0.17763.7678
affected
10.0.17763.0 before 10.0.17763.7678
affected
10.0.17763.0 before 10.0.17763.7678
affected
10.0.20348.0 before 10.0.20348.4052
affected
10.0.19044.0 before 10.0.19044.6216
affected
10.0.22621.0 before 10.0.22621.5768
affected
10.0.19045.0 before 10.0.19045.6216
affected
10.0.26100.0 before 10.0.26100.4946
affected
10.0.22631.0 before 10.0.22631.5768
affected
10.0.22631.0 before 10.0.22631.5768
affected
10.0.25398.0 before 10.0.25398.1791
affected
10.0.26100.0 before 10.0.26100.4946
affected
10.0.26100.0 before 10.0.26100.4946
affected
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53716 (Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability) vendor-advisory
cve.org
(CVE-2025-53716)
nvd.nist.gov
(CVE-2025-53716)
Download JSON