CVE-2013-3868: Microsoft Active Directory Lightweight Directory Service

Medium severity, CVSS 5.0. EPSS: 37.1% chance of exploitation in the next 30 days.

Microsoft Active Directory Lightweight Directory Service (AD LDS) on Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows 8 and Active Directory Services on Windows Server 2008 SP2 and R2 SP1 and Server 2012 allow remote attackers to cause a denial of service (LDAP directory-service outage) via a crafted LDAP query, aka "Remote Anonymous DoS Vulnerability."

Affected products

  • Microsoft Active Directory Lightweight Directory Service: affected versions not specified
  • Microsoft Windows 7: any version
  • Microsoft Windows 8: affected versions not specified
  • Microsoft Windows Server 2008: any version
  • Microsoft Windows Server 2012: affected versions not specified
  • Microsoft Windows Vista: any version

Published 2013-09-11. Last modified 2026-06-16.