CVE-2025-49716
published 2025-07-08CVE-2025-49716: Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network.
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.33%
68.0th percentile
Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.27820 | 6.1.7601.27820 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.23418 | 6.0.6003.23418 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.25573 | 6.2.9200.25573 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.22676 | 6.3.9600.22676 |
| microsoft | windows_server_2016 | < 10.0.14393.8246 | 10.0.14393.8246 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.8246 | 10.0.14393.8246 |
| microsoft | windows_server_2019 | < 10.0.17763.7558 | 10.0.17763.7558 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.7558 | 10.0.17763.7558 |
| microsoft | windows_server_2022 | < 10.0.20348.3932 | 10.0.20348.3932 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.3932 | 10.0.20348.3932 |
| microsoft | windows_server_2022_23h2 | < 10.0.25398.1732 | 10.0.25398.1732 |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_21h2 | — | — |
| msrc | windows_10_version_22h2 | — | — |
| msrc | windows_11_version_22h2 | — | — |
| msrc | windows_11_version_23h2 | — | — |
| msrc | windows_server_2008 | — | — |
| msrc | windows_server_2008_for_32-bit_systems_service_pack_2 | — | — |
| msrc | windows_server_2008_for_x64-based_systems_service_pack_2 | — | — |
| msrc | windows_server_2008_r2 | — | — |
| msrc | windows_server_2008_r2_for_x64-based_systems_service_pack_1 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-884w-hqx3-6fj7: Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network
ghsa_unreviewed·2025-07-08
CVE-2025-49716 [MEDIUM] CWE-400 GHSA-884w-hqx3-6fj7: Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network
Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network.
Microsoft
Windows Netlogon Denial of Service Vulnerability
vendor_msrc·2025-07-08·CVSS 7.5
CVE-2025-49716 [HIGH] CWE-400 Windows Netlogon Denial of Service Vulnerability
Windows Netlogon Denial of Service Vulnerability
Description: Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to invest time in repeated exploitation attempts through sending constant or intermittent data.
FAQ: What actions do I need to take to be protected from this vulnerability?
To mitigate this vulnerability, a code change was made in the July 2025 Windows Security Updates for all other Server platforms from Windows Server 2008 SP2 to Windows Server 2022, inclusive.
After this change, some file and print service software can be affec
Microsoft
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
vendor_msrc·2025-05-13·CVSS 5.9
CVE-2025-29954 [MEDIUM] CWE-400 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
Description: Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to invest time in repeated exploitation attempts through sending constant or intermittent data.
FAQ: Are there additional actions I need to take to harden my system against unauthenticated RPC calls?
Possibly. Refer to KB5066014—Netlogon RPC Hardening (CVE-2025-49716) - Microsoft Support for additional follow-up actions you might need to take.
Windows LDAP -
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-07-08
Published