Sceawere
Vulnerability Detail
CVE-2026-54113UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Windows Kernel Resource Exhaustion
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 7h ago
- Vendor
- Microsoft
- Product
- Windows 10 Version 1607
- Attack Type
- CWE-770: Allocation of Resources Without Limits or Throttling
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-08-11T17:18:03.457Z",
"pubdate": "2026-08-11T17:18:03.457Z",
"executiveSummary": "This vulnerability involves an allocation of resources without limits or throttling flaw residing within the Windows Kernel.\nAn unauthorized remote attacker can leverage this security deficiency to induce a denial of service condition over a network.\nThe affected system experiences severe resource depletion due to uncontrolled consumption, impacting operational availability and system stability.\nRisk implications include potential service outages and degraded performance of critical kernel-level operations.\nThe attacker capabilities are limited to causing denial of service without requiring prior authentication or elevated privileges.\nExploitation requirements include network connectivity to the target system to dispatch crafted requests or data streams that trigger the unbounded resource allocation.",
"technicalDetails": "The root cause of the vulnerability stems from the absence of proper resource management, rate limiting, or throttling mechanisms within specific routines of the Windows Kernel.\nWhen processing incoming requests or transactions over a network, the vulnerable component continuously allocates memory or other system resources dynamically without enforcing upper bounds.\nThe vulnerable component is identified as the Windows Kernel, which handles core operating system services and network-facing packet processing or connection management.\nAuthentication requirements are none, as the attack can be initiated by an unauthorized entity.\nPrivilege requirements are nonexistent; the adversary does not need prior access or elevated privileges on the target host.\nNetwork exposure is present, allowing remote adversaries to interact directly with the vulnerable interfaces exposed by the operating system.\nDuring the attack flow, the adversary transmits a sustained stream of specially crafted network payloads designed to force the Windows Kernel into continuous allocation cycles.\nAs the kernel allocates resources continuously to service these incoming requests without releasing or throttling them, available system memory or object handles are rapidly exhausted.\nThe payload behavior focuses entirely on exhausting finite kernel-level resources rather than executing arbitrary code or achieving privilege escalation.\nThe post-exploitation impact culminates in a denial of service state, which may manifest as system unresponsiveness, resource starvation, or a bug check resulting in a system crash."
}