Skip to main content

Insufficient Resource Pool

CVE-2025-27479

Severity High
Score 7.5/10

Summary

Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • HIGH

CWE-410 - Insufficient Resource Pool

The software's resource pool is not large enough to handle peak demand, which allows an attacker to prevent others from accessing the resource by using a (relatively) large number of requests for resources.

References

Advisory Timeline

  • Published