Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability

Plan PatchCVSS 8.8CVE-2026-62785Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

A heap-based buffer overflow vulnerability exists in the Windows LDAP (Lightweight Directory Access Protocol) implementation. An attacker can send a specially crafted LDAP protocol message over the network to trigger the overflow and execute arbitrary code with system privileges. The vulnerability affects Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025. All versions are vulnerable; Microsoft has released patches for all supported versions.

What this means
What could happen
An attacker could exploit a heap buffer overflow in Windows LDAP to run arbitrary code on your server or workstation with system privileges. This could allow the attacker to compromise domain authentication, steal credentials, or disrupt services that depend on Active Directory or LDAP.
Who's at risk
This vulnerability affects Windows workstations and servers that run LDAP services, including domain controllers, member servers, and any systems with LDAP client software. Organizations using Active Directory are directly affected. Critical systems include domain controllers, file servers, application servers, and engineering workstations in utility environments that authenticate through Windows domain services.
How it could be exploited
An attacker sends a specially crafted LDAP protocol message over the network to a Windows system running LDAP services (typically a domain controller, member server, or workstation with LDAP client functionality enabled). The malicious packet triggers a heap buffer overflow in the LDAP parser, allowing the attacker to execute arbitrary code without authentication.
Prerequisites
  • Network access to port 389 (LDAP) or 636 (LDAPS)
  • LDAP service must be active on the target system (standard on domain controllers and member servers)
remotely exploitableno authentication requiredlow complexityaffects authentication infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Remediation & Mitigation
0/9
Do now
0/1
WORKAROUNDRestrict network access to LDAP ports 389 (unencrypted) and 636 (encrypted) to only authorized domain controllers and member servers using firewall rules
Schedule — requires maintenance window
0/8

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXUpdate Windows Server 2016 to Build 10.0.14393.9418 or later
Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9115 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5499 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33296 or later
All products
HOTFIXUpdate Windows 10 Version 1809 to Build 10.0.17763.9115 or later
HOTFIXUpdate Windows 10 Version 21H2 to Build 10.0.19044.7663 or later
HOTFIXUpdate Windows 10 Version 22H2 to Build 10.0.19045.7663 or later
HOTFIXUpdate Windows 11 to the latest build number for your version (23H2, 24H2, 25H2, or 26H1)
API: /api/v1/advisories/85193b41-8ef1-4951-b36b-2873d11d836f

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability | CVSS 8.8 - OTPulse