Description
Out-of-bounds read in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper buffer handling in the Windows LDAP component allows an unauthorized entity to trigger an out‑of‑bounds read, resulting in a denial of service. When the vulnerable code processes an LDAP request, the read can corrupt internal state or cause a crash, which brings down the LDAP service for all clients. The weakness is a classic out‑of‑bounds read (CWE‑125). The impact is loss of availability for the LDAP directory service and any applications that rely on it. No data exfiltration or code execution is described, so confidentiality or integrity are not directly affected by this flaw.

Affected Systems

Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012 through 2025, including server core installations; all listed builds are affected until a patch is applied.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. EPSS data is not available, so current exploitation probability cannot be quantified, but the lack of a KEV listing suggests no known public exploit yet. The attack vector is likely remote over the network via LDAP on standard ports (389/636). An attacker who can send LDAP traffic to a target machine can trigger the denial of service without needing elevated privileges.

Generated by OpenCVE AI on September 8, 2026 at 21:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft update that addresses CVE-2026-69428. The fix can be obtained from Microsoft's security update guide or the Windows Update Catalog.
  • Until the patch is installed, restrict LDAP traffic by configuring firewall rules to allow only trusted IP addresses or by blocking ports 389 and 636 to all other hosts.
  • Monitor the LDAP service for crashes or service restarts by watching Windows Event Log for relevant error IDs (such as 7023 or 7024) and configure alerts to notify administrators of repeated failures.

Generated by OpenCVE AI on September 8, 2026 at 21:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
Title Windows LDAP - Lightweight Directory Access Protocol Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-125
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows 10 21h2 Windows 10 22h2 Windows 11 23h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2012 Windows Server 2012 R2 Windows Server 2016 Windows Server 2019 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T20:48:27.751Z

Reserved: 2026-08-03T20:59:32.784Z

Link: CVE-2026-69428

cve-icon Vulnrichment

Updated: 2026-09-08T20:48:22.109Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:19:06.407

Modified: 2026-09-08T21:18:32.177

Link: CVE-2026-69428

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T21:45:17Z

Weaknesses