Windows Kerberos Denial of Service Vulnerability

MonitorCVSS 5.3CVE-2026-42914Jun 9, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

An out-of-bounds read vulnerability in the Windows Kerberos subsystem allows an authorized attacker to send a specially crafted Kerberos message that causes a crash (denial of service). The vulnerability affects Windows 10, Windows 11, and Windows Server 2016, 2019, 2022, and 2025 systems. Exploitation is less likely and requires valid network credentials.

What this means
What could happen
An authenticated attacker could crash the Kerberos authentication service on a Windows server, temporarily blocking logins and access to network resources until the system is rebooted.
Who's at risk
Windows administrators and organizations relying on Kerberos-based authentication should care about this issue. It affects Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 systems that serve as domain controllers or domain-joined workstations where Kerberos is the authentication mechanism.
How it could be exploited
An attacker with valid network credentials could send a specially crafted Kerberos message to the domain controller or member server's Kerberos service (port 88), triggering an out-of-bounds read that causes the service to crash and deny authentication to legitimate users.
Prerequisites
  • Valid Windows network credentials (user or service account)
  • Network access to Kerberos port 88 (TCP/UDP)
  • Target system running affected Windows version
Remotely exploitableAuthentication requiredDenial of service impactAffects authentication infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.8880
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.8880
Windows Server 2019All versionsBuild 10.0.17763.8880
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.8880
Windows Server 2022All versionsBuild 10.0.20348.5256
Remediation & Mitigation
0/7
Schedule — requires maintenance window
0/7

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 (all installations) to Build 10.0.17763.8880 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 (all installations) to Build 10.0.20348.5256 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.32995 or later
All products
HOTFIXUpdate Windows 10 Version 1809 (32-bit and x64) to Build 10.0.17763.8880 or later
HOTFIXUpdate Windows 10 Version 21H2 to Build 10.0.19044.7417 or later
HOTFIXUpdate Windows 10 Version 22H2 to Build 10.0.19045.7417 or later
HOTFIXUpdate Windows 11 (all versions) to the June 2026 security update or later
API: /api/v1/advisories/0ab5a041-74c9-4357-8735-358530efd72a

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Kerberos Denial of Service Vulnerability | CVSS 5.3 - OTPulse