CVE-2025-53716NULL Pointer Dereference in Microsoft Windows 10 Version 1809

Severity
6.5MEDIUMNVD
EPSS
0.3%
top 45.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12

Description

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages17 packages

NVDmicrosoft/windows< 10.0.17763.7678+3
NVDmicrosoft/windows_10_1809< 10.0.17763.7678
NVDmicrosoft/windows_10_21h2< 10.0.19044.6216
NVDmicrosoft/windows_10_22h2< 10.0.19045.6216
NVDmicrosoft/windows_11_22h2< 10.0.22621.5768

🔴Vulnerability Details

2
CVEList
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability2025-08-12
GHSA
GHSA-xhvx-9w5h-q8q6: Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network2025-08-12

📋Vendor Advisories

1
Microsoft
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability2025-08-12

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft August 2025 Patch Tuesday fixes one zero-day, 107 flaws2025-08-12
CVE-2025-53716 — NULL Pointer Dereference in Microsoft | cvebase