Executive brief
A vulnerability exists in the Windows implementation of the Lightweight Directory Access Protocol (LDAP), which is used for managing and accessing directory information like user accounts and permissions. An authorized user on the network could exploit this flaw to tamper with directory data. While this does not allow for data theft or service outages, it could allow an attacker to modify records they should not have access to, potentially compromising the integrity of organizational directory services.
Technical details
A tampering vulnerability exists in Windows LDAP due to improper input validation (CWE-20). An attacker with low-privileged network access (PR:L) can exploit this flaw by sending specially crafted LDAP requests to a vulnerable server. Successful exploitation allows the attacker to modify or tamper with directory data, though it does not directly lead to information disclosure or a denial-of-service condition. The vulnerability affects a wide range of Windows client and server versions, including Windows 10, Windows 11, and Windows Server 2016. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
- Microsoft Windows Server 2016 All versions
Timeline
- 2026-01-13: disclosed
- 2026-01-13: advisory