Windows LDAP - Lightweight Directory Access Protocol Denial of Service Vulnerability

Plan PatchCVSS 7.5CVE-2026-69428Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

An out-of-bounds read vulnerability in Windows LDAP (Lightweight Directory Access Protocol) allows a remote attacker without authentication to cause a denial of service condition. The vulnerability can be triggered over the network, affecting Windows servers running LDAP services and workstations configured as LDAP clients.

What this means
What could happen
An attacker could send malformed LDAP requests to crash or hang domain controllers, file servers, or other systems running LDAP services, disrupting authentication, directory lookups, and any processes dependent on LDAP availability. This could prevent users from logging in or accessing shared resources.
Who's at risk
This affects IT staff managing Windows Server domain controllers, file servers, and any Windows workstations or servers with LDAP services enabled. Primary concern is for organizations running Windows Server 2016, 2019, 2022, or 2025 domain controllers, as these are the core of authentication and directory services. Windows 10 and 11 systems with LDAP client/service features are also affected. Sectors: utilities, municipal systems, manufacturing, healthcare—any organization with Windows-based directory infrastructure.
How it could be exploited
An attacker on the network sends a specially crafted LDAP protocol request to a system running LDAP services (typically port 389 or 636 for LDAPS). The out-of-bounds read in the LDAP parser causes the service to crash or become unresponsive, denying service to legitimate clients.
Prerequisites
  • Network access to port 389 (LDAP) or port 636 (LDAPS)
  • Target system running Windows LDAP service (typically domain controllers, but also some application servers and workstations with LDAP features enabled)
  • No valid credentials required
remotely exploitableno authentication requiredlow complexityaffects authentication infrastructure
Exploitability
Some exploitation risk — EPSS score 1.1%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict network access to LDAP ports (389 for standard LDAP, 636 for LDAPS) using firewalls or network ACLs to only authorized clients and admin workstations
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows to the September 2026 security patch or later: Windows Server 2019/2016 to Build 10.0.17763.9245 or 10.0.14393.9512 respectively; Windows Server 2022 to Build 10.0.20348.5622; Windows Server 2025 to Build 10.0.26100.33438; Windows 10/11 versions to their respective fixed builds listed in the advisory
Long-term hardening
0/1
HARDENINGDisable LDAP service on systems that do not require it
API: /api/v1/advisories/eb362ed2-ba9b-4f63-8310-e7d77ccc0684

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows LDAP - Lightweight Directory Access Protocol Denial of Service Vulnerability | CVSS 7.5 - OTPulse