CVE-2025-32724

Published Jun 10, 2025

Last updated 2 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-32724 is a denial-of-service vulnerability affecting the Windows Local Security Authority Subsystem Service (LSASS). The vulnerability stems from uncontrolled resource consumption within LSASS. An unauthorized attacker can exploit this flaw over a network to disrupt system operations. Successful exploitation of CVE-2025-32724 can lead to a denial-of-service condition, as LSASS is a critical component responsible for enforcing security policies. Microsoft released a security update as part of the June 2025 Patch Tuesday to address this vulnerability. Applying this update is advised to protect against potential attacks.

Description
Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
Source
secure@microsoft.com
NVD status
Analyzed
Products
windows_10_1507, windows_10_1607, windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_22h2, windows_11_23h2, windows_11_24h2, windows_server_2008, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2022_23h2, windows_server_2025

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-400

Social media

Hype score
Not currently trending
  1. win-dDoS exploits CVE-2025-32724 to turn 10,000 domain controllers into DDoS slaves. AEGIS grok needs a red team, kill switch and transparency report or it’s $200M lobbyist lunch money

    @agentsentia

    12 Aug 2025

    114 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 【公開するなよ】公開されたドメインコントローラ(DC)をDDoSのエージェントにすることが可能な脆弱性、CVE-2025-32724について。SafeBreach社報告。攻撃技法をWin-DDoSと命名。細工されたRPCコールをDCに送り、標的のI

    @__kokumoto

    11 Aug 2025

    4937 Impressions

    22 Retweets

    82 Likes

    22 Bookmarks

    1 Reply

    0 Quotes

  3. Entre mayo y julio de 2025, Microsoft parchó varias vulnerabilidades críticas, incluyendo: CVE-2025-26673: Consumo excesivo de recursos en LDAP. CVE-2025-32724: Ataque DoS sobre LSASS. CVE-2025-49716: Ataque DoS en Netlogon. CVE-2025-49722: Ataque DoS en el spooler de impresi

    @SoyITPro

    11 Aug 2025

    4616 Impressions

    22 Retweets

    105 Likes

    30 Bookmarks

    1 Reply

    0 Quotes

  4. New Win-DDoS attack exploits LDAP referral flaws in Windows domain controllers to create massive DDoS botnets without credentials or code execution. Vulnerabilities CVE-2025-26673 & CVE-2025-32724 involved. #WinDDoS #LDAPFlaws #Windows https://t.co/otPjNaCBeU

    @TweetThreatNews

    10 Aug 2025

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-32724 Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. https://t.co/rXVOsIxM8Z

    @CVEnew

    10 Jun 2025

    163 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.