← back
CVE-2025-59259

Windows Local Session Manager (LSM) Denial of Service Vulnerability

CVSS 6.5 MEDIUMEPSS 1.4%CWE-1287
In short

A flaw in Windows Local Session Manager allows an authorized user on a network to crash or disable the service, making it unavailable to other users. This can disrupt normal computer operations.

Technical detail

Improper input validation in Windows LSM permits an authorized network attacker to send crafted input that triggers a denial of service condition. The vulnerability requires valid credentials and network access, resulting in service unavailability rather than data compromise.

Summary generated and translated by AI from the official description.
Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →