CVE-2025-50172
published 2025-08-12CVE-2025-50172: Allocation of resources without limits or throttling in Windows DirectX allows an authorized attacker to deny service over a network.
medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
Allocation of resources without limits or throttling in Windows DirectX allows an authorized attacker to deny service over a network.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1809 | < 10.0.17763.7678 | 10.0.17763.7678 |
| microsoft | windows_10_21h2 | < 10.0.19044.6216 | 10.0.19044.6216 |
| microsoft | windows_10_22h2 | < 10.0.19045.6216 | 10.0.19045.6216 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.7678 | 10.0.17763.7678 |
| microsoft | windows_10_version_21h2 | >= 10.0.19044.0 < 10.0.19044.6216 | 10.0.19044.6216 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.6216 | 10.0.19045.6216 |
| microsoft | windows_11_22h2 | < 10.0.22621.5768 | 10.0.22621.5768 |
| microsoft | windows_11_23h2 | < 10.0.22631.5768 | 10.0.22631.5768 |
| microsoft | windows_11_24h2 | < 10.0.26100.4851 | 10.0.26100.4851 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.5768 | 10.0.22621.5768 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.5768 | 10.0.22631.5768 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.5768 | 10.0.22631.5768 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.4946 | 10.0.26100.4946 |
| microsoft | windows_server_2019 | < 10.0.17763.7678 | 10.0.17763.7678 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.7678 | 10.0.17763.7678 |
| microsoft | windows_server_2022 | < 10.0.20348.3989 | 10.0.20348.3989 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.4052 | 10.0.20348.4052 |
| microsoft | windows_server_2022_23h2 | < 10.0.25398.1791 | 10.0.25398.1791 |
| microsoft | windows_server_2025 | < 10.0.26100.4851 | 10.0.26100.4851 |
| microsoft | windows_server_2025 | >= 10.0.26100.0 < 10.0.26100.4946 | 10.0.26100.4946 |
| msrc | azl3_kernel_6.6.57.1-7_on_azure_linux_3.0 | — | — |
| msrc | azl3_kernel_6.6.64.2-1_on_azure_linux_3.0 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_21h2 | — | — |
| msrc | windows_10_version_22h2 | — | — |
Microsoft
DirectX Graphics Kernel Denial of Service Vulnerability
vendor_msrc·2025-08-12·CVSS 6.5
CVE-2025-50172 [MEDIUM] CWE-770 DirectX Graphics Kernel Denial of Service Vulnerability
DirectX Graphics Kernel Denial of Service Vulnerability
Description: Allocation of resources without limits or throttling in Windows DirectX allows an authorized attacker to deny service over a network.
Windows DirectX: Windows DirectX
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5063877
Reference: https://support.microsoft.com/help/5063877
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5063880
Reference: https://support.microsoft.com/help/5063880
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5063812
Reference: https://support.
Microsoft
RDMA/bnxt_re: Fix a possible memory leak
vendor_msrc·2024-11-12·CVSS 5.5
CVE-2024-50172 [MEDIUM] CWE-401 RDMA/bnxt_re: Fix a possible memory leak
RDMA/bnxt_re: Fix a possible memory leak
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Linux: Linux
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/
GHSA
GHSA-6c4g-4jgx-9qwp: Allocation of resources without limits or throttling in Windows DirectX allows an authorized attacker to deny service over a network
ghsa_unreviewed·2025-08-12
CVE-2025-50172 [MEDIUM] CWE-770 GHSA-6c4g-4jgx-9qwp: Allocation of resources without limits or throttling in Windows DirectX allows an authorized attacker to deny service over a network
Allocation of resources without limits or throttling in Windows DirectX allows an authorized attacker to deny service over a network.
No detection rules found.
No public exploits indexed.
2025-08-12
Published