CVE-2025-26673

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 8, 2025
Updated: Apr 9, 2025
CWE ID 400

Summary

CVE-2025-26673 is a newly identified vulnerability affecting Windows LDAP servers. This issue allows unauthorized attackers to cause uncontrolled resource consumption, leading to a denial-of-service (DoS) condition over a network. By exploiting this vulnerability, attackers can exhaust the server's resources, making it unresponsive to legitimate users. This can result in significant downtime and negatively impact the availability of critical network services. Users are strongly advised to apply the necessary security patches as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 10
  • Microsoft Windows 11
  • Microsoft Windows Server 2008 R2
  • Microsoft Windows Server 2022

Affected Vendors

  • Microsoft