Windows Kerberos Denial of Service Vulnerability
An out-of-bounds read vulnerability exists in the Windows Kerberos authentication component. When processing a specially crafted Kerberos packet, the affected systems read memory beyond the bounds of the intended buffer, causing a denial of service. The Kerberos service may crash, disrupting network authentication for domain-joined machines and preventing legitimate users from logging in or accessing domain resources until the service recovers. The vulnerability affects all commonly deployed Windows versions including Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025.
- Network access to Kerberos authentication port (typically port 88 TCP/UDP)
- Target must be a Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 system
Patching may require device reboot — plan for process interruption
/api/v1/advisories/c2db0781-4871-4d91-a64a-a59b5d9a9d4bGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.