lsass

  1. CVE-2025-53809: LSASS DoS via Improper Input Validation in Windows

    Microsoft’s security advisory for CVE-2025-53809 warns that improper input validation in the Windows Local Security Authority Subsystem Service (LSASS) can be abused by an authorized attacker to cause a denial of service (DoS) over a network, putting authentication services and domain...
  2. CVE-2025-54895: Local Privilege Escalation in Windows NEGOEX/SPNEGO

    Microsoft’s advisory for CVE-2025-54895 warns that an integer overflow or wraparound in the SPNEGO Extended Negotiation (NEGOEX) security mechanism can be triggered by an authorized local actor to elevate privileges, turning a legitimate local account into a pathway to SYSTEM-level control if...
  3. CVE-2025-53716: Patch LSASS DoS Now to Protect Domain Controllers

    Title: New LSASS DoS (CVE-2025-53716) — What admins need to know now By WindowsForum.com security desk — August 12, 2025 Summary A null-pointer dereference vulnerability in the Windows Local Security Authority Subsystem Service (LSASS) — tracked as CVE-2025-53716 in Microsoft’s Security Update...
  4. Win-DDoS: Hardening Windows Domain Controllers Against LDAP/CLDAP DoS Attacks

    SafeBreach Labs’ disclosure of four newly discovered Windows denial-of-service (DoS) flaws — and the novel “Win‑DDoS” technique they describe for turning exposed domain controllers into DDoS amplifiers — forces a hard look at how organizations harden their identity plane, patch critical servers...
  5. LDAPNightmare: Zero-Click Windows DoS on Domain Controllers (CVE-2024-49113)

    A new class of Windows denial-of-service attacks revealed at DEF CON has forced a hard reckoning for enterprise defenders: vulnerabilities in LDAP handling can not only crash individual servers, they can be chained into zero-click attack flows that target Domain Controllers (DCs) and potentially...
  6. Windows 11 KB5064489 Update: Security Fixes & Stability Enhancements for 24H2

    Microsoft has released an out-of-band update, KB5064489, for Windows 11 version 24H2, bringing the OS build to 26100.4656. This update addresses critical issues that necessitated immediate attention outside the regular update schedule. Key Improvements and Fixes: Security Enhancements: The...
  7. Windows 11 Stability Boost with KB5060614 & KB5059693 Dynamic Updates

    Microsoft’s strategy for evolving Windows 11 is no longer marked by the headline-grabbing features that dominated past releases. Instead, their latest Dynamic updates—namely KB5060614 and KB5059693—focus on fine-tuning the OS’s setup and recovery processes. While these updates aren’t likely to...
  8. Understanding Windows Dynamic Updates: Essential Patches for Setup and Recovery

    Few updates in Windows ecosystems are as silently critical—and often misunderstood—as the so-called "Dynamic Updates." Last week, Microsoft quietly pushed out two new Dynamic Update packages for Windows 11 24H2 and Windows Server 2025: KB5060614 (Setup Dynamic Update) and KB5059693 (Safe OS...
  9. Microsoft’s Emergency Update Fixes Windows 10 BitLocker Recovery Glitch Caused by Intel TXT

    Microsoft’s swift release of an emergency out-of-band update aimed at fixing the notorious BitLocker recovery issue in Windows 10 marks another chapter in the operating system’s complex ongoing relationship with hardware security and enterprise reliability. For countless administrators and...
  10. CVE-2024-49126: Understanding Windows LSASS RCE Vulnerability

    The cybersecurity landscape is always evolving, and recently a new vulnerability has caught the attention of security experts and Windows users alike: CVE-2024-49126. This Remote Code Execution vulnerability specifically affects the Local Security Authority Subsystem Service (LSASS) in Windows...
  11. J

    Lsass.exe constantly reading registry for DefaultAuthLevel (NAME NOT FOUND - in Process Monitor)

    I see it relates to DCOM Default Authentication Level, which has in total, 7 fields in the Component Services Windows admin tool. That is in this order, from top of the list to the bottom as it appears; Default, None, Call, Connect, Packet, Packet integrity and Packet Privacy. I only see one...
  12. Windows 11 Build 22000.1879 (KB 5025298): Key Updates and Fixes in Release Preview

    Hello, WindowsForum community! There's exciting news for Windows 11 enthusiasts and insiders: Microsoft has just released Windows 11 Build 22000.1879 (KB 5025298) to the Release Preview Channel. Let's dive into the key updates and improvements this latest build brings. Key Improvements and...
  13. Why Local Security Authority Subsystem Service can't be deactivated

    Hi all, I have been searching for some technical post to understand why LSASS can't be deactivated. Okay, it is responsible for enforcing the security policy on the system, but I want some deep sight why the system restarts after deactivate it. Thanks!
  14. MS17-004 - Important: Security Update for Local Security Authority Subsystem Service...

    Severity Rating: Important Revision Note: V1.0 (January 10, 2017): Bulletin Published Summary: A denial of service vulnerability exists in the way the Local Security Authority Subsystem Service (LSASS) handles authentication requests. An attacker who successfully exploited the vulnerability...
  15. Memory leak in LSASS process on Windows Server 2012 R2-based domain controllers and AD LDS...

    Continue reading...
  16. LSASS deadlocks cause Windows Server 2012 R2 or Windows Server 2012 not to respond

    Continue reading...
  17. Lsass.exe process crashes and error code 255 is logged because of a CNF NTDS Settings...

    Link Removed
  18. Lsass.exe process crashes on a computer that's running Windows 7 or Windows Server 2008 R2 SP1

    Continue reading...
  19. Lsass.exe process crashes and error code 255 is logged because of a CNF NTDS Settings object...

    Continue reading...
  20. High CPU utilization by the Svchost.exe process and the Lsass.exe process in the Remote Desktop sess

    Fixes an issue in which both the Svchost.exe process and the Lsass.exe process consume lots of CPU resources. This issues occurs after you remotely connect to a computer that is running Windows 7 or Windows Server 2008 R2. More...