Windows Kerberos
by Microsoft
CVEs (27)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-24297 | Med | 0.42 | 6.5 | 0.00 | Mar 10, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kerberos allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2025-47978 | Med | 0.42 | 6.5 | 0.02 | Jul 8, 2025 | Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network. | ||
| CVE-2024-43547 | Med | 0.42 | 6.5 | 0.01 | Oct 8, 2024 | Windows Kerberos Information Disclosure Vulnerability | ||
| CVE-2022-37967 | Hig | 0.40 | 7.2 | 0.04 | Nov 9, 2022 | Windows Kerberos Elevation of Privilege Vulnerability | ||
| CVE-2025-21350 | Med | 0.39 | 5.9 | 0.02 | Feb 11, 2025 | Windows Kerberos Denial of Service Vulnerability | ||
| CVE-2026-20833 | Med | 0.36 | 5.5 | 0.01 | Jan 13, 2026 | Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally. | ||
| CVE-2026-42914 | Med | 0.34 | 5.3 | 0.01 | Jun 9, 2026 | Windows Kerberos Denial of Service Vulnerability |
- risk 0.42cvss 6.5epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kerberos allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.42cvss 6.5epss 0.02
Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.
- risk 0.42cvss 6.5epss 0.01
Windows Kerberos Information Disclosure Vulnerability
- risk 0.40cvss 7.2epss 0.04
Windows Kerberos Elevation of Privilege Vulnerability
- risk 0.39cvss 5.9epss 0.02
Windows Kerberos Denial of Service Vulnerability
- risk 0.36cvss 5.5epss 0.01
Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally.
- risk 0.34cvss 5.3epss 0.01
Windows Kerberos Denial of Service Vulnerability
Page 2 of 2