CVE-2026-69428
massUnauthenticated Out-of-Bounds Read Denial-of-Service in Windows LDAP
CVE-2026-69428 is an out-of-bounds read (CWE-125) vulnerability in the Microsoft Windows LDAP (Lightweight Directory Access Protocol) component, assigned by Microsoft ([email protected]). An unauthenticated remote attacker can trigger it by sending crafted network traffic to a system's LDAP service, causing the service to read past the bounds of an allocated memory buffer. The result is a denial of service of the affected system's LDAP service (CVSS 3.1: 7.5 High, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), with no confidentiality or integrity impact. Any Windows system running the LDAP service is affected — most commonly Windows Server domain controllers and other directory-service servers — but the provided data does not list specific affected or fixed version ranges, so defenders should consult Microsoft's advisory for those details. Exploitation status: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS assigns a 1.1% probability of exploitation within 30 days (65th percentile), so no in-the-wild exploitation is currently known.
What to do: Apply Microsoft's security update for CVE-2026-69428 per Microsoft's advisory, prioritizing domain controllers and other servers whose LDAP service is reachable from untrusted networks; verify the definitive affected and fixed build numbers in the advisory, since they are not included in this data. Until patched, restrict network access to LDAP (typically TCP/UDP 389 and LDAPS 636) with firewall rules so only trusted hosts can connect, and monitor for LDAP service crashes or unexpected restarts.
| Microsoft Windows LDAP (Lightweight Directory Access Protocol) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.