CVE-2025-29957
published 2025-05-13CVE-2025-29957: Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally.
PriorityP425medium6.2CVSS 3.1
AVLACLPRNUINSUCNINAH
EPSS
0.50%
39.4th percentile
Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.21014 | 10.0.10240.21014 |
| microsoft | windows_10_1607 | < 10.0.14393.8066 | 10.0.14393.8066 |
| microsoft | windows_10_1809 | < 10.0.17763.7314 | 10.0.17763.7314 |
| microsoft | windows_10_21h2 | < 10.0.19044.5854 | 10.0.19044.5854 |
| microsoft | windows_10_22h2 | < 10.0.19045.5854 | 10.0.19045.5854 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.21014 | 10.0.10240.21014 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.8066 | 10.0.14393.8066 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.7314 | 10.0.17763.7314 |
| microsoft | windows_10_version_21h2 | >= 10.0.19044.0 < 10.0.19044.5854 | 10.0.19044.5854 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.5854 | 10.0.19045.5854 |
| microsoft | windows_11_22h2 | < 10.0.22621.5335 | 10.0.22621.5335 |
| microsoft | windows_11_23h2 | < 10.0.22631.5335 | 10.0.22631.5335 |
| microsoft | windows_11_24h2 | < 10.0.26100.4061 | 10.0.26100.4061 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.5335 | 10.0.22621.5335 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.5335 | 10.0.22631.5335 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.5335 | 10.0.22631.5335 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.4061 | 10.0.26100.4061 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.27729 | 6.1.7601.27729 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.23279 | 6.0.6003.23279 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.25475 | 6.2.9200.25475 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.22577 | 6.3.9600.22577 |
| microsoft | windows_server_2016 | < 10.0.14393.8066 | 10.0.14393.8066 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.8066 | 10.0.14393.8066 |
CVSS provenance
nvdv3.16.2MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_msrc6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rgrg-qwpp-28j8: Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally
ghsa_unreviewed·2025-05-13
CVE-2025-29957 [MEDIUM] CWE-400 GHSA-rgrg-qwpp-28j8: Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally
Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally.
Microsoft
Windows Deployment Services Denial of Service Vulnerability
vendor_msrc·2025-05-13·CVSS 6.2
CVE-2025-29957 [MEDIUM] CWE-400 Windows Deployment Services Denial of Service Vulnerability
Windows Deployment Services Denial of Service Vulnerability
Description: Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally.
Windows Deployment Services: Windows Deployment Services
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5058392
Reference: https://support.microsoft.com/help/5058392
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5058385
Reference: https://support.microsoft.com/help/5058385
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5058500
Reference: htt
No detection rules found.
No public exploits indexed.
2025-05-13
Published