Executive brief
A vulnerability exists in the Windows implementation of the Lightweight Directory Access Protocol (LDAP), a service used for managing and accessing directory information. An attacker who already has local access to a system could exploit this flaw to cause a system crash or service outage. This results in a denial-of-service condition, potentially disrupting business operations and user authentication services.
Technical details
A null pointer dereference vulnerability (CWE-476) exists within the Microsoft Windows LDAP (Lightweight Directory Access Protocol) implementation. The flaw is triggered when the service fails to properly validate a pointer before dereferencing it during local operations. An attacker with low-privileged local access can exploit this vulnerability to crash the LDAP service or the host operating system. The attack vector is local, requiring no user interaction, and results in a high impact on system availability. Microsoft has released information regarding this vulnerability via their Security Update Guide.
Affected products
- Microsoft Windows LDAP
Timeline
- 2026-05-12: disclosed: Initial disclosure by Microsoft and NVD publication.