ZeroHour

CVE-2026-69732

mass

Heap-Based Buffer Overflow in Windows Link Layer Topology Discovery (LLTD)

CVSS 3.1
8.1 high
EPSS
<1%p52
Published
()
Modified
AI analysis

CVE-2026-69732 is a heap-based buffer overflow (CWE-122) in the Windows Link Layer Topology Discovery (LLTD) protocol, the component Windows uses for network mapping and device discovery. An unauthorized, unauthenticated attacker who can send network traffic to an affected host can trigger the flaw with specially crafted LLTD packets; the CVSS scoring (high attack complexity, no privileges required, no user interaction) indicates the trigger conditions are non-trivial but require no credentials or user action. Successful exploitation allows remote code execution on the target with high impact on confidentiality, integrity, and availability. All Windows systems that expose the LLTD protocol are potentially affected, but the attack surface is network-adjacent rather than internet-facing, since LLTD discovery traffic typically operates on the local subnet rather than across the open internet. There is no evidence of active exploitation: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS assigns only a 0.7% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69732 via Windows Update when available, prioritizing hosts on shared or untrusted LANs (guest Wi-Fi, branch offices, shared office networks) where unauthenticated peers can send LLTD traffic directly. As an interim mitigation, restrict LLTD discovery traffic to trusted segments using host or network firewall rules. Since no exploitation is currently known, patching within a normal maintenance cycle appears reasonable, but monitor Microsoft's advisory for any change in exploitation status or affected-version details.

Affected
Microsoft Windows (Link Layer Topology Discovery protocol component)
Estimated exposure
mass≈1 billion Windows devices (LLTD is a standard Windows component), though only hosts reachable on an attacker's local network segment are practically exposed — LLTD ships as part of Windows, whose installed base exceeds a billion active devices, but exploitation requires the attacker to reach the target from the same local network rather than from the internet, so the practically exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Link Layer Topology Discovery Protocol allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.