Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability
Plan PatchCVSS 8.8CVE-2026-62785Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary
A heap-based buffer overflow vulnerability exists in the Windows LDAP (Lightweight Directory Access Protocol) implementation. An attacker can send a specially crafted LDAP protocol message over the network to trigger the overflow and execute arbitrary code with system privileges. The vulnerability affects Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025. All versions are vulnerable; Microsoft has released patches for all supported versions.
What this means
What could happen
An attacker could exploit a heap buffer overflow in Windows LDAP to run arbitrary code on your server or workstation with system privileges. This could allow the attacker to compromise domain authentication, steal credentials, or disrupt services that depend on Active Directory or LDAP.
Who's at risk
This vulnerability affects Windows workstations and servers that run LDAP services, including domain controllers, member servers, and any systems with LDAP client software. Organizations using Active Directory are directly affected. Critical systems include domain controllers, file servers, application servers, and engineering workstations in utility environments that authenticate through Windows domain services.
How it could be exploited
An attacker sends a specially crafted LDAP protocol message over the network to a Windows system running LDAP services (typically a domain controller, member server, or workstation with LDAP client functionality enabled). The malicious packet triggers a heap buffer overflow in the LDAP parser, allowing the attacker to execute arbitrary code without authentication.
Prerequisites
- Network access to port 389 (LDAP) or 636 (LDAPS)
- LDAP service must be active on the target system (standard on domain controllers and member servers)
remotely exploitableno authentication requiredlow complexityaffects authentication infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/9
Do now
0/1WORKAROUNDRestrict network access to LDAP ports 389 (unencrypted) and 636 (encrypted) to only authorized domain controllers and member servers using firewall rules
Schedule — requires maintenance window
0/8Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXUpdate Windows Server 2016 to Build 10.0.14393.9418 or later
Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9115 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5499 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33296 or later
All products
HOTFIXUpdate Windows 10 Version 1809 to Build 10.0.17763.9115 or later
HOTFIXUpdate Windows 10 Version 21H2 to Build 10.0.19044.7663 or later
HOTFIXUpdate Windows 10 Version 22H2 to Build 10.0.19045.7663 or later
HOTFIXUpdate Windows 11 to the latest build number for your version (23H2, 24H2, 25H2, or 26H1)
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/85193b41-8ef1-4951-b36b-2873d11d836fGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.