CVE-2025-53805
published 2025-09-09CVE-2025-53805: Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network.
high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_11_22h2 | < 10.0.22621.5909 | 10.0.22621.5909 |
| microsoft | windows_11_23h2 | < 10.0.22631.5909 | 10.0.22631.5909 |
| microsoft | windows_11_24h2 | < 10.0.26100.6508 | 10.0.26100.6508 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.5909 | 10.0.22621.5909 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.5909 | 10.0.22631.5909 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.5909 | 10.0.22631.5909 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.6584 | 10.0.26100.6584 |
| microsoft | windows_server_2022 | < 10.0.20348.4106 | 10.0.20348.4106 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.4171 | 10.0.20348.4171 |
| microsoft | windows_server_2022_23h2 | < 10.0.25398.1849 | 10.0.25398.1849 |
| microsoft | windows_server_2025 | < 10.0.26100.6508 | 10.0.26100.6508 |
| microsoft | windows_server_2025 | >= 10.0.26100.0 < 10.0.26100.6584 | 10.0.26100.6584 |
| msrc | windows_11_version_22h2_for_arm64-based_systems | — | — |
| msrc | windows_11_version_22h2_for_x64-based_systems | — | — |
| msrc | windows_11_version_23h2_for_arm64-based_systems | — | — |
| msrc | windows_11_version_23h2_for_x64-based_systems | — | — |
| msrc | windows_11_version_24h2_for_arm64-based_systems | — | — |
| msrc | windows_11_version_24h2_for_x64-based_systems | — | — |
| msrc | windows_server_2022 | — | — |
| msrc | windows_server_2022_23h2_edition | — | — |
| msrc | windows_server_2025 | — | — |
GHSA
GHSA-j53j-mff4-vmcg: Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network
ghsa_unreviewed·2025-09-09
CVE-2025-53805 [HIGH] CWE-125 GHSA-j53j-mff4-vmcg: Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network
Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network.
Microsoft
HTTP.sys Denial of Service Vulnerability
vendor_msrc·2025-09-09·CVSS 7.5
CVE-2025-53805 [HIGH] CWE-125 HTTP.sys Denial of Service Vulnerability
HTTP.sys Denial of Service Vulnerability
Description: Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network.
Windows Internet Information Services: Windows Internet Information Services
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5065432
Reference: https://support.microsoft.com/help/5065432
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5065306
Reference: https://support.microsoft.com/help/5065306
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5065431
Reference:
No detection rules found.
No public exploits indexed.
2025-09-09
Published