cbcvebase.
CVE-2026-21243
published 2026-02-10

CVE-2026-21243: Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.

Affected

11 ranges
VendorProductVersion rangeFixed in
microsoftwindows_server_2019< 10.0.17763.838910.0.17763.8389
microsoftwindows_server_2019>= 10.0.17763.0 < 10.0.17763.838910.0.17763.8389
microsoftwindows_server_2022< 10.0.20348.471110.0.20348.4711
microsoftwindows_server_2022>= 10.0.20348.0 < 10.0.20348.477310.0.20348.4773
microsoftwindows_server_2022_23h2< 10.0.25398.214910.0.25398.2149
microsoftwindows_server_2025< 10.0.26100.3231310.0.26100.32313
microsoftwindows_server_2025>= 10.0.26100.0 < 10.0.26100.3237010.0.26100.32370
msrcwindows_server_2019
msrcwindows_server_2022
msrcwindows_server_2022_23h2_edition
msrcwindows_server_2025