Impact
An improper buffer handling in the Windows LDAP component allows an unauthorized entity to trigger an out‑of‑bounds read, resulting in a denial of service. When the vulnerable code processes an LDAP request, the read can corrupt internal state or cause a crash, which brings down the LDAP service for all clients. The weakness is a classic out‑of‑bounds read (CWE‑125). The impact is loss of availability for the LDAP directory service and any applications that rely on it. No data exfiltration or code execution is described, so confidentiality or integrity are not directly affected by this flaw.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012 through 2025, including server core installations; all listed builds are affected until a patch is applied.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. EPSS data is not available, so current exploitation probability cannot be quantified, but the lack of a KEV listing suggests no known public exploit yet. The attack vector is likely remote over the network via LDAP on standard ports (389/636). An attacker who can send LDAP traffic to a target machine can trigger the denial of service without needing elevated privileges.
OpenCVE Enrichment