Junglewise Threat Intelligence

CVE-2026-34339: Microsoft Windows LDAP null pointer dereference denial of service

CVE-2026-34339 · Severity: medium · CVSS 5.5 · Published 2026-05-12

Vendors: Microsoft.

Executive brief

A vulnerability exists in the Windows implementation of the Lightweight Directory Access Protocol (LDAP), a service used for managing and accessing directory information. An attacker who already has local access to a system could exploit this flaw to cause a system crash or service outage. This results in a denial-of-service condition, potentially disrupting business operations and user authentication services.

Technical details

A null pointer dereference vulnerability (CWE-476) exists within the Microsoft Windows LDAP (Lightweight Directory Access Protocol) implementation. The flaw is triggered when the service fails to properly validate a pointer before dereferencing it during local operations. An attacker with low-privileged local access can exploit this vulnerability to crash the LDAP service or the host operating system. The attack vector is local, requiring no user interaction, and results in a high impact on system availability. Microsoft has released information regarding this vulnerability via their Security Update Guide.

Affected products

  • Microsoft Windows LDAP

Timeline

  • 2026-05-12: disclosed: Initial disclosure by Microsoft and NVD publication.

References