First published: Tue Apr 08 2025(Updated: )
<p>Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.</p>
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Server | ||
Microsoft Windows Server 2012 R2 | ||
Windows 10 | =1607 | |
Microsoft Windows Server 2025 | ||
Windows 10 | =21H2 | |
Microsoft Windows Server 2008 R2 | ||
Microsoft Windows Server 2016 | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Windows 10 | =22H2 | |
Windows 11 | =24H2 | |
Microsoft Windows Server 2019 | ||
Windows 10 | =1607 | |
Windows 11 | =22H2 | |
Microsoft Windows Server 2025 | ||
Microsoft Windows Server 2008 R2 | ||
Microsoft Windows Server | ||
Microsoft Windows Server 2022 23H2 | ||
Microsoft Windows Server | ||
Windows 11 | =24H2 | |
Windows 10 | =21H2 | |
Windows 11 | =23H2 | |
Windows 11 | =23H2 | |
Windows 10 | =1809 | |
Windows 10 | =22H2 | |
Windows 10 | =21H2 | |
Microsoft Windows Server 2012 R2 | ||
Microsoft Windows Server 2022 | ||
Windows 11 | =22H2 | |
Windows 10 | =1809 | |
Microsoft Windows Server 2019 | ||
Microsoft Windows Server 2016 | ||
Windows 10 | =22H2 | |
Microsoft Windows Server 2022 | ||
Microsoft Windows Server | ||
Windows 10 | ||
Windows 10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27469 is classified as a denial-of-service vulnerability that allows an unauthorized attacker to disrupt service in Windows LDAP.
To fix CVE-2025-27469, apply the appropriate patches provided by Microsoft for the affected Windows Server and Windows 10 versions.
CVE-2025-27469 affects multiple versions of Windows including Windows Server 2008, 2012, 2016, 2019, 2022, Windows 10, and Windows 11.
Systems running outdated versions of Windows with LDAP services enabled are particularly vulnerable to CVE-2025-27469.
Yes, CVE-2025-27469 allows unauthorized attackers to exploit the vulnerability remotely over a network.