Executive brief
Windows Link Layer Topology Discovery (LLTD) is a network protocol built into Windows systems for device discovery and identification on local networks. A heap-based buffer overflow in this protocol allows a remote attacker to execute arbitrary code on vulnerable systems without authentication, potentially compromising Windows computers on a network.
Technical details
A heap-based buffer overflow vulnerability exists in the Windows Link Layer Topology Discovery Protocol implementation, a core network service that runs with elevated privileges. The vulnerability is triggered by a specially crafted network packet sent over the network, requiring no prior authentication or user interaction. An attacker on the same network or with network access can craft a malicious packet to overflow a heap buffer and achieve remote code execution with the privileges of the affected service. Microsoft has released security updates to patch this vulnerability.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed