CVE-2026-69732
massHeap-Based Buffer Overflow in Windows Link Layer Topology Discovery (LLTD)
CVE-2026-69732 is a heap-based buffer overflow (CWE-122) in the Windows Link Layer Topology Discovery (LLTD) protocol, the component Windows uses for network mapping and device discovery. An unauthorized, unauthenticated attacker who can send network traffic to an affected host can trigger the flaw with specially crafted LLTD packets; the CVSS scoring (high attack complexity, no privileges required, no user interaction) indicates the trigger conditions are non-trivial but require no credentials or user action. Successful exploitation allows remote code execution on the target with high impact on confidentiality, integrity, and availability. All Windows systems that expose the LLTD protocol are potentially affected, but the attack surface is network-adjacent rather than internet-facing, since LLTD discovery traffic typically operates on the local subnet rather than across the open internet. There is no evidence of active exploitation: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS assigns only a 0.7% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for CVE-2026-69732 via Windows Update when available, prioritizing hosts on shared or untrusted LANs (guest Wi-Fi, branch offices, shared office networks) where unauthenticated peers can send LLTD traffic directly. As an interim mitigation, restrict LLTD discovery traffic to trusted segments using host or network firewall rules. Since no exploitation is currently known, patching within a normal maintenance cycle appears reasonable, but monitor Microsoft's advisory for any change in exploitation status or affected-version details.
| Microsoft Windows (Link Layer Topology Discovery protocol component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Link Layer Topology Discovery Protocol allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.