May 2026: Windows Link-Layer Discovery Protocol (LLDP) Elevation of Privilege Vulnerability
CVE-2026-34341 Published on May 12, 2026
Windows Link-Layer Discovery Protocol (LLDP) Elevation of Privilege Vulnerability
Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally.
Weakness Type
What is a Double-free Vulnerability?
The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations. When a program calls free() twice with the same argument, the program's memory management data structures become corrupted. This corruption can cause the program to crash or, in some circumstances, cause two later calls to malloc() to return the same pointer. If malloc() returns the same value twice and the program later gives the attacker control over the data that is written into this doubly-allocated memory, the program becomes vulnerable to a buffer overflow attack.
CVE-2026-34341 has been classified to as a Double-free vulnerability or weakness.
Products Associated with CVE-2026-34341
Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.
Affected Versions
Microsoft Windows 10 Version 1607:- Version 10.0.14393.0 and below 10.0.14393.9140 is affected.
- Version 10.0.17763.0 and below 10.0.17763.8755 is affected.
- Version 10.0.19044.0 and below 10.0.19044.7291 is affected.
- Version 10.0.19045.0 and below 10.0.19045.7291 is affected.
- Version 10.0.22631.0 and below 10.0.22631.7079 is affected.
- Version 10.0.22631.0 and below 10.0.22631.7079 is affected.
- Version 10.0.26100.0 and below 10.0.26100.8457 is affected.
- Version 10.0.26200.0 and below 10.0.26200.8457 is affected.
- Version 10.0.28000.0 and below 10.0.28000.2113 is affected.
- Version 6.2.9200.0 and below 6.2.9200.26079 is affected.
- Version 6.2.9200.0 and below 6.2.9200.26079 is affected.
- Version 6.3.9600.0 and below 6.3.9600.23181 is affected.
- Version 6.3.9600.0 and below 6.3.9600.23181 is affected.
- Version 10.0.14393.0 and below 10.0.14393.9140 is affected.
- Version 10.0.14393.0 and below 10.0.14393.9140 is affected.
- Version 10.0.17763.0 and below 10.0.17763.8755 is affected.
- Version 10.0.17763.0 and below 10.0.17763.8755 is affected.
- Version 10.0.20348.0 and below 10.0.20348.5139 is affected.
- Version 10.0.25398.0 and below 10.0.25398.2330 is affected.
- Version 10.0.26100.0 and below 10.0.26100.32860 is affected.
- Version 10.0.26100.0 and below 10.0.26100.32860 is affected.