← back
CVE-2025-58729mediumCWE-1287

Windows Local Session Manager (LSM) Denial of Service Vulnerability

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.5epss 1.1%
exploitation probability
1.1%top 38% of all CVEs
observed exploitation
nono source reports it
In short

Windows Local Session Manager has a flaw where it doesn't properly check certain user input, allowing someone with access to cause the service to crash or become unavailable over the network.

Technical detail

CWE-1287 improper input validation in LSM enables an authenticated attacker to craft malicious input that bypasses validation checks, resulting in denial of service of the Local Session Manager component accessible over the network.

Summary generated and translated by AI from the official description.
Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C