Executive brief
A security vulnerability exists in Microsoft Active Directory Domain Services, the central system used by organizations to manage users, computers, and network permissions. An attacker with basic user credentials could exploit this flaw to run unauthorized code on the domain controller. This could lead to a complete takeover of the corporate network, allowing the attacker to steal sensitive data or disrupt business operations.
Technical details
A stack-based buffer overflow (CWE-121) exists in Microsoft Active Directory Domain Services. The vulnerability is triggered when the service improperly handles specially crafted network requests, leading to memory corruption. An attacker with low-privileged domain credentials can exploit this over the network without any user interaction. Successful exploitation allows for remote code execution with high privileges on the affected domain controller. Microsoft has released security updates to address this issue; administrators should apply the latest cumulative updates for Windows Server.
Affected products
- Microsoft Active Directory Domain Services
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory