Impact
Windows LDAP in Microsoft Windows exposes a use‑after‑free vulnerability that permits an unauthorized attacker to execute code remotely by sending a specially crafted LDAP request over a network. The flaw is classified as CWE‑416, indicating that free memory was reused, enabling arbitrary code execution. If successfully exploited, an attacker can gain the security context of the LDAP service, compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
Products affected include Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and several server editions such as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both full and server‑core installations. All listed versions run the vulnerable LDAP component as part of the operating system kernel.
Risk and Exploitability
The CVSS score of 8.8 reflects a high overall severity, with high impact and low effort. EPSS is not available, so current exploitation probability cannot be quantified, and the vulnerability is not yet listed in CISA’s KEV catalog. The likely attack vector is an external network connection to the LDAP service (TCP ports 389/636). Successful exploitation requires only network reachability to the target machine, with no local user interaction, making this a critical risk for exposed servers or devices in untrusted networks.
OpenCVE Enrichment