PT-2025-20974 · Unknown+1 · Web Threat Defense+1
Vladimir Lagunov
·
Published
2025-05-13
·
Updated
2026-03-16
·
CVE-2025-29971
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
Web Threat Defense versions prior to May 2025 update
Description:
The issue is an out-of-bounds read in Web Threat Defense (WTD.sys) that allows an unauthorized attacker to deny service over a network. This can be exploited by remote attackers to crash systems, posing a kernel-level denial-of-service threat.
Recommendations:
For versions prior to the May 2025 update, apply the patch KB5058411 to resolve the issue. As a temporary workaround, consider restricting network access to minimize the risk of exploitation.
Fix
DoS
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Web Threat Defense
Windows