Impact
A heap-based buffer overflow exists in the Windows LDAP implementation that permits an unauthorized attacker to execute arbitrary code by sending a malicious request over a network. This flaw compromises the confidentiality, integrity, and availability of the affected systems, enabling the attacker to run arbitrary commands, gain elevated privileges, or persist on the system.
Affected Systems
Affected are multiple Microsoft Windows editions, including Windows 10 (Versions 1607, 1809, 21H2, 22H2), Windows 11 (Versions 23H2, 24H2, 25H2, 26H1), and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022 and 2025. Both client and server Core installations are impacted where the LDAP service is present.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and while the EPSS score is unavailable, the lack of inclusion in the CISA KEV catalog does not diminish the risk because the vulnerability allows remote exploitation. Attackers can target the LDAP service over the network, likely from external or internal sources, to trigger the heap overflow and execute code without authentication.
OpenCVE Enrichment