Thanks, Serge. The CVE references are helpful.
I’d just clarify two points:
The vulnerabilities are network-exploitable, but saying they are “directly exploitable from the Internet” assumes the vulnerable KDC Proxy endpoint is actually Internet-reachable.
Also, regarding the “undocumented side effects” of disabling KPSSVC, could you share which Windows features or scenarios you’ve observed being affected? That would help determine whether disabling KPSSVC has dependencies beyond the documented KDC Proxy use cases.
For now, Microsoft’s supported remediation for CVE-2024-43639 and CVE-2025-33071 remains applying the applicable security updates rather than relying on disabling KPSSVC.
Hopefully a Microsoft moderator can also clarify whether KPSSVC has any additional supported dependencies administrators should consider before disabling it.