CVE-2019-0972: Local Security Authority Subsystem Service Denial of Service Vulnerability
Local Security Authority Subsystem Service Denial of Service Vulnerability
Other sources
This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attacker sends a specially crafted authentication request. A remote attacker who successfully exploited this vulnerability could cause a denial of service on the target system's LSASS service, which triggers an automatic reboot of the system. The security update addresses the vulnerability by changing the way that LSASS handles specially crafted authentication requests.
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-0972?
CVE-2019-0972 is classified as a denial of service vulnerability which affects the Local Security Authority Subsystem Service.
How do I fix CVE-2019-0972?
To fix CVE-2019-0972, you should apply the latest security updates provided by Microsoft for the affected versions of Windows.
What versions of Windows are affected by CVE-2019-0972?
CVE-2019-0972 affects various versions of Windows, including Windows 7, 8.1, 10, and several Server editions.
What happens if I don't address CVE-2019-0972?
Failing to address CVE-2019-0972 could leave your system susceptible to denial of service attacks, potentially leading to service interruptions.
Who can exploit CVE-2019-0972?
CVE-2019-0972 can be exploited by an authenticated attacker who sends a specially crafted authentication request to the system.