Impact
The vulnerability is a null pointer dereference in the Windows LDAP component. When triggered, it causes the LDAP service to crash, leading to a local denial of service. This flaw cannot directly compromise data or execute code; its primary effect is service interruption for users relying on LDAP. The weakness is identified as CWE‑476.
Affected Systems
The flaw affects a wide range of Microsoft Windows releases, including Windows 10 versions 1607, 1809, 21H2, 22H2, Windows 11 versions 23H2, 24H2, 25H2, 22H3, 26H1, and Windows Server 2016, 2019, 2022, 2025, and the 23H2 Server edition, across x86, x64, and ARM64 architectures as listed in the CNA data.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score is not available, suggesting no public exploitation data yet. The risk is limited to environments where an attacker has local privileged access and can interact with the LDAP service, as the attack requires authorization. The flaw is not listed in the CISA KEV catalog, and no remote exploit path is documented, so the immediate threat to unprivileged users remains low but should be mitigated promptly in environments that rely on LDAP.
OpenCVE Enrichment