You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2025-21376
About this tag
CVE-2025-21376 is a critical remote code execution vulnerability in the Windows Lightweight Directory Access Protocol (LDAP) implementation. Disclosed in Microsoft's February 2025 Patch Tuesday, it is considered wormable and could allow attackers to execute arbitrary code remotely via specially crafted requests exploiting a race condition. This poses significant risks to enterprise and personal Windows systems that rely on LDAP for directory services. Discussions on WindowsForum cover the technical details, affected systems, and practical mitigation steps, including applying the security updates released by Microsoft. Users are advised to prioritize patching to protect against potential exploitation.
A serious security vulnerability has been identified in the Windows LDAP (Lightweight Directory Access Protocol) implementation, posing a significant threat to both enterprise and personal Windows systems. Designated as CVE-2025-21376, this so-called “wormable” vulnerability could allow...
Microsoft has released its February 2025 Patch Tuesday security updates, addressing a total of 55 vulnerabilities across various Windows products. Among these, 3 are classified as critical, and 4 are zero-day vulnerabilities, with 2 actively exploited in the wild.
Critical Vulnerabilities...
On February 11, 2025, the Microsoft Security Response Center (MSRC) published details regarding a new vulnerability identified as CVE-2025-21376. This vulnerability, affecting the Windows Lightweight Directory Access Protocol (LDAP) implementation, poses a remote code execution (RCE) risk—a...