Sceawere

Vulnerability Detail

CVE-2026-54113UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Windows Kernel Resource Exhaustion

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
7h ago
Vendor
Microsoft
Product
Windows 10 Version 1607
Attack Type
CWE-770: Allocation of Resources Without Limits or Throttling
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-11T17:18:03.457Z",
  "pubdate": "2026-08-11T17:18:03.457Z",
  "executiveSummary": "This vulnerability involves an allocation of resources without limits or throttling flaw residing within the Windows Kernel.\nAn unauthorized remote attacker can leverage this security deficiency to induce a denial of service condition over a network.\nThe affected system experiences severe resource depletion due to uncontrolled consumption, impacting operational availability and system stability.\nRisk implications include potential service outages and degraded performance of critical kernel-level operations.\nThe attacker capabilities are limited to causing denial of service without requiring prior authentication or elevated privileges.\nExploitation requirements include network connectivity to the target system to dispatch crafted requests or data streams that trigger the unbounded resource allocation.",
  "technicalDetails": "The root cause of the vulnerability stems from the absence of proper resource management, rate limiting, or throttling mechanisms within specific routines of the Windows Kernel.\nWhen processing incoming requests or transactions over a network, the vulnerable component continuously allocates memory or other system resources dynamically without enforcing upper bounds.\nThe vulnerable component is identified as the Windows Kernel, which handles core operating system services and network-facing packet processing or connection management.\nAuthentication requirements are none, as the attack can be initiated by an unauthorized entity.\nPrivilege requirements are nonexistent; the adversary does not need prior access or elevated privileges on the target host.\nNetwork exposure is present, allowing remote adversaries to interact directly with the vulnerable interfaces exposed by the operating system.\nDuring the attack flow, the adversary transmits a sustained stream of specially crafted network payloads designed to force the Windows Kernel into continuous allocation cycles.\nAs the kernel allocates resources continuously to service these incoming requests without releasing or throttling them, available system memory or object handles are rapidly exhausted.\nThe payload behavior focuses entirely on exhausting finite kernel-level resources rather than executing arbitrary code or achieving privilege escalation.\nThe post-exploitation impact culminates in a denial of service state, which may manifest as system unresponsiveness, resource starvation, or a bug check resulting in a system crash."
}
CVE-2026-54113: Windows Kernel Resource Exhaustion (HIGH Severity, CVSS: 7.5) - Sceawere