CVE-2025-32724

Published Jun 10, 2025

Last updated 8 months ago

Overview

Description
Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
Source
secure@microsoft.com
NVD status
Analyzed
Products
windows_10_1507, windows_10_1607, windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_22h2, windows_11_23h2, windows_11_24h2, windows_server_2008, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2022_23h2, windows_server_2025

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-400

Social media

Hype score
Not currently trending
  1. win-dDoS exploits CVE-2025-32724 to turn 10,000 domain controllers into DDoS slaves. AEGIS grok needs a red team, kill switch and transparency report or it’s $200M lobbyist lunch money

    @agentsentia

    12 Aug 2025

    114 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 【公開するなよ】公開されたドメインコントローラ(DC)をDDoSのエージェントにすることが可能な脆弱性、CVE-2025-32724について。SafeBreach社報告。攻撃技法をWin-DDoSと命名。細工されたRPCコールをDCに送り、標的のI

    @__kokumoto

    11 Aug 2025

    4937 Impressions

    22 Retweets

    82 Likes

    22 Bookmarks

    1 Reply

    0 Quotes

  3. Entre mayo y julio de 2025, Microsoft parchó varias vulnerabilidades críticas, incluyendo: CVE-2025-26673: Consumo excesivo de recursos en LDAP. CVE-2025-32724: Ataque DoS sobre LSASS. CVE-2025-49716: Ataque DoS en Netlogon. CVE-2025-49722: Ataque DoS en el spooler de impresi

    @SoyITPro

    11 Aug 2025

    4616 Impressions

    22 Retweets

    105 Likes

    30 Bookmarks

    1 Reply

    0 Quotes

  4. New Win-DDoS attack exploits LDAP referral flaws in Windows domain controllers to create massive DDoS botnets without credentials or code execution. Vulnerabilities CVE-2025-26673 & CVE-2025-32724 involved. #WinDDoS #LDAPFlaws #Windows https://t.co/otPjNaCBeU

    @TweetThreatNews

    10 Aug 2025

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-32724 Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. https://t.co/rXVOsIxM8Z

    @CVEnew

    10 Jun 2025

    163 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.