Medium6.7
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H

PT-2025-01: NULL pointer dereference leads to Denial of Service (DoS) in Microsoft Windows 11 22H2

Error type:

Vulnerability vector:

  • Base vulnerability score (CVSSv3.1): CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H

  • Severity (CVSSv3.1): 5.9 (medium)

  • Base vulnerability score (CVSSv4.0): CVSS:4.0/ AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H

  • Severity (CVSSv4.0): 6.7 (medium)

Description:

The vulnerability was discovered in Microsoft Windows 11 22H2, versions 19045.5371.

The discovered vulnerability allows an attacker to create the conditions for a local Denial of Service (DoS).

Vulnerability status: Confirmed by vendor

Date of vulnerability discovery: 22.01.2025

Recommendations:

Microsoft has decided not to release a fix for this issue to the public right away because it did not meet the criteria for an immediate security update. However, they have committed to including a fix for this issue in the next version of the product

To mitigate the vulnerability, it is also recommended to disable Microsoft OneDrive if the product is not in use.

Additional information:

Microsoft has shared the report with the team responsible for maintaining the product or service.

The responsible team will take appropriate action as needed to help keep customers protected.

Researcher: Marat Gayanov (Positive Technologies)

Identifiers:

BDU:2025-03858

Vendor:

Microsoft Corporation

Vulnerable product:

Windows 10 22H2

Vulnerable versions:

26100.2894