CVE-2026-49799
Analyzed Analyzed - Analysis Complete

Uncontrolled Resource Consumption in Windows LSASS

Vulnerability report for CVE-2026-49799, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-22

Assigner: Microsoft Corporation

Description

Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-22
Generated
2026-08-03
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 22 associated CPEs
Vendor Product Version / Range
microsoft windows_server_2012 r2
microsoft windows_server_2012 *
microsoft windows_11_26h1 to 10.0.28000.2269 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_server_2016 to 10.0.14393.9339 (exc)
microsoft windows_server_2019 to 10.0.17763.9020 (exc)
microsoft windows_server_2022 to 10.0.20348.5386 (exc)
microsoft windows_server_2025 to 10.0.26100.33158 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-49799 is a vulnerability in the Windows Local Security Authority Subsystem Service (LSASS). It involves uncontrolled resource consumption, which means an attacker can exploit this flaw to exhaust system resources.

An authorized attacker with low privileges (indicated by PR:L in the CVSS vector) can send crafted requests over a network to trigger excessive resource usage in LSASS. This leads to a denial of service (DoS) condition, where the affected system becomes unresponsive or crashes.

Detection Guidance

The provided context does not include specific detection methods or commands for identifying this vulnerability on a network or system. Detection may involve monitoring unusual resource consumption by the Windows Local Security Authority Subsystem Service (LSASS) or checking for abnormal network traffic patterns associated with denial-of-service attempts.

For precise detection guidance, refer to Microsoft's official documentation or security tools that monitor LSASS behavior and resource usage.

Impact Analysis

This vulnerability can impact you in the following ways:

  • Denial of Service (DoS): An attacker can cause the LSASS service to consume excessive resources, leading to system instability or crashes. This can disrupt critical services relying on LSASS, such as authentication and security policies.
  • Network-based exploitation: Since the attack vector is network-based (AV:N), an attacker does not need physical access to the system. They can exploit this vulnerability remotely if they have authorized access to the network.
  • Operational downtime: If the system crashes or becomes unresponsive, it may require manual intervention to restore normal operations, leading to downtime and potential loss of productivity.
Compliance Impact

This vulnerability may affect compliance with common standards and regulations in the following ways:

  • GDPR: Under GDPR, organizations must ensure the availability and resilience of processing systems. A denial of service attack exploiting this vulnerability could disrupt services, potentially violating Article 32, which requires measures to ensure ongoing confidentiality, integrity, availability, and resilience of processing systems.
  • HIPAA: For organizations handling protected health information (PHI), HIPAA requires ensuring the availability of systems. A DoS condition caused by this vulnerability could lead to unauthorized disruptions, potentially violating the HIPAA Security Rule, which mandates safeguards to protect the availability of electronic PHI.
  • Other standards: Compliance frameworks like ISO 27001 or NIST SP 800-53 emphasize the importance of system availability and resilience. Exploitation of this vulnerability could result in non-compliance with controls related to system and service availability.

However, the specific impact on compliance depends on the context of the affected system, the data it processes, and the organization's regulatory obligations.

Mitigation Strategies

The provided context does not specify immediate mitigation steps for this vulnerability. However, general best practices for mitigating uncontrolled resource consumption vulnerabilities in LSASS may include:

  • Apply the latest security updates from Microsoft as soon as they are available. Refer to the Microsoft Update Guide for CVE-2026-49799 for patches.
  • Restrict network access to systems running LSASS to authorized users only, particularly those with low privileges (PR:L).
  • Monitor LSASS resource usage for unusual spikes that could indicate an attack.
  • Implement network-level protections, such as rate limiting or intrusion detection systems, to detect and block denial-of-service attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-49799. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart