Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to win a race condition.
How could an attacker exploit this vulnerability? An unauthenticated attacker could send a specially crafted request to a vulnerable LDAP server. Successful exploitation could result in a buffer overflow which could be leveraged to achieve remote code execution.
🎯 Affected products37
- Windows 10 Version 1607 for 32-bit Systems
- Windows 10 Version 1607 for x64-based Systems
- Windows 10 Version 1809 for 32-bit Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 21H2 for 32-bit Systems
- Windows 10 Version 21H2 for ARM64-based Systems
- Windows 10 Version 21H2 for x64-based Systems
- Windows 10 Version 22H2 for 32-bit Systems
- Windows 10 Version 22H2 for ARM64-based Systems
- Windows 10 Version 22H2 for x64-based Systems
- Windows 10 for 32-bit Systems
- Windows 10 for x64-based Systems
- Windows 11 Version 22H2 for ARM64-based Systems
- Windows 11 Version 22H2 for x64-based Systems
- Windows 11 Version 23H2 for ARM64-based Systems
- Windows 11 Version 23H2 for x64-based Systems
- Windows 11 Version 24H2 for ARM64-based Systems
- Windows 11 Version 24H2 for x64-based Systems
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
- Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 for x64-based Systems Service Pack 2
- Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
- Windows Server 2012
- Windows Server 2012 (Server Core installation)
- Windows Server 2012 R2
- Windows Server 2012 R2 (Server Core installation)
- Windows Server 2016
- Windows Server 2016 (Server Core installation)
- +7 more not shown
✅ Remediation
KB5052000 (Security Update) — fixed build 10.0.17763.6893 KB5051979 (Security Update) — fixed build 10.0.20348.3207 KB5052106 (SecurityHotpatchUpdate) — fixed build 10.0.20348.3148 KB5051974 (Security Update) — fixed build 10.0.19044.5487 KB5051989 (Security Update) — fixed build 10.0.22621.4890 KB5051974 (Security Update) — fixed build 10.0.19045.5487 KB5051987 (Security Update) — fixed build 10.0.26100.3194 KB5052105 (SecurityHotpatchUpdate) — fixed build 10.0.26100.3107 KB5051989 (Security Update) — fixed build 10.0.22631.4890 KB5051980 (Security Update) — fixed build 10.0.25398.1425 KB5052040 (Security Update) — fixed build 10.0.10240.20915 KB5052006 (Security Update) — fixed build 10.0.14393.7785 KB5052038 (Monthly Rollup) — fixed build 6.0.6003.23117 KB5052072 (Security Only) — fixed build 6.0.6003.23117 KB5052016 (Monthly Rollup) — fixed build 6.1.7601.27566 KB5052032 (Security Only) — fixed build 6.1.7601.27566 KB5052020 (Monthly Rollup) — fixed build 6.2.9200.25317 KB5052042 (Monthly Rollup) — fixed build 6.3.9600.22417
🔗 References (31)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21376
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5052000
- referencehttps://support.microsoft.com/help/5052000
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5051979
- referencehttps://support.microsoft.com/help/5051979
- referencehttps://support.microsoft.com/help/5052106
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5051974
- referencehttps://support.microsoft.com/help/5051974
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5051989
- referencehttps://support.microsoft.com/help/5051989
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5051987
- referencehttps://support.microsoft.com/help/5051987
- referencehttps://support.microsoft.com/help/5052105
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5051980
- referencehttps://support.microsoft.com/help/5051980
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5052040
- referencehttps://support.microsoft.com/help/5052040
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5052006
- referencehttps://support.microsoft.com/help/5052006
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5052038
- referencehttps://support.microsoft.com/help/5052038
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5052072
- referencehttps://support.microsoft.com/help/5052072
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5052016
- referencehttps://support.microsoft.com/help/5052016
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5052032
- referencehttps://support.microsoft.com/help/5052032
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5052020
- referencehttps://support.microsoft.com/help/5052020
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5052042
- referencehttps://support.microsoft.com/help/5052042