cbcvebase.
CVE-2025-26670
published 2025-04-08

CVE-2025-26670: Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.

PriorityP260high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
10.43%
95.2th percentile
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.

Affected

47 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1507< 10.0.10240.2097810.0.10240.20978
microsoftwindows_10_1607< 10.0.14393.796910.0.14393.7969
microsoftwindows_10_1809< 10.0.17763.713610.0.17763.7136
microsoftwindows_10_21h2< 10.0.19044.573710.0.19044.5737
microsoftwindows_10_22h2< 10.0.19045.573710.0.19045.5737
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.2097810.0.10240.20978
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.796910.0.14393.7969
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.713610.0.17763.7136
microsoftwindows_10_version_21h2>= 10.0.19044.0 < 10.0.19044.573710.0.19044.5737
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.573710.0.19045.5737
microsoftwindows_11_22h2< 10.0.22621.518910.0.22621.5189
microsoftwindows_11_23h2< 10.0.22631.518910.0.22631.5189
microsoftwindows_11_24h2< 10.0.26100.377510.0.26100.3775
microsoftwindows_11_version_22h2>= 10.0.22621.0 < 10.0.22621.518910.0.22621.5189
microsoftwindows_11_version_22h3>= 10.0.22631.0 < 10.0.22631.518910.0.22631.5189
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.518910.0.22631.5189
microsoftwindows_11_version_24h2>= 10.0.26100.0 < 10.0.26100.377510.0.26100.3775
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.7601.0 < 6.1.7601.276706.1.7601.27670
microsoftwindows_server_2008_service_pack_2>= 6.0.6003.0 < 6.0.6003.232206.0.6003.23220
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.254236.2.9200.25423
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.225236.3.9600.22523
microsoftwindows_server_2016< 10.0.14393.796910.0.14393.7969
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.796910.0.14393.7969

Detection & IOCsextracted from sources · hover to see the quote

  • Attack vector is network-based, unauthenticated; detect sequential specially crafted LDAP requests to a vulnerable LDAP server (default port 389/636) that may indicate exploitation attempts targeting a use-after-free condition.
  • Exploitation requires winning a race condition (AC:H); monitor for repeated, rapid, sequential LDAP request bursts from unauthenticated sources as a behavioral indicator.
  • ·Exploitation likelihood is rated 'More Likely' for latest software releases despite no known active exploitation at time of publication; prioritize patching accordingly.
  • ·The vulnerability resides in the Windows LDAP CLIENT, not the server — attack surface is client systems connecting to attacker-controlled or compromised LDAP servers, not just exposed LDAP servers.

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.