Executive brief
A security vulnerability exists in Windows Active Directory, the service used by organizations to manage users, computers, and network permissions. An authorized user on the same local network could exploit this flaw to run unauthorized code on the server. This could lead to a full takeover of the identity management system, potentially compromising all accounts and data within the corporate network.
Technical details
A remote code execution vulnerability exists in Windows Active Directory due to improper input validation (CWE-20). The vulnerability is reachable over an adjacent network and requires the attacker to have low-level authorized credentials (PR:L). An attacker who successfully exploits this vulnerability could achieve full system compromise (High Confidentiality, Integrity, and Availability impact). The issue affects multiple versions of Windows Server from 2012 R2 through 2025. Microsoft has released security updates to address this flaw; administrators should apply the latest cumulative updates for their respective server versions.
Affected products
- Microsoft Windows Server 2012 R2 versions up to (excluding) 6.3.9600.23132
- Microsoft Windows Server 2016 versions up to (excluding) 10.0.14393.9060
- Microsoft Windows Server 2019 versions up to (excluding) 10.0.17763.8644
- Microsoft Windows Server 2022 versions up to (excluding) 10.0.20348.5020
- Microsoft Windows Server 2022, 23H2 Edition versions up to (excluding) 10.0.25398.2274
- Microsoft Windows Server 2025 versions up to (excluding) 10.0.26100.32690
Timeline
- 2026-04-14: disclosed: Initial disclosure by Microsoft
- 2026-04-14: advisory: Microsoft Security Update Guide published