Executive brief
A critical vulnerability has been identified in Microsoft Active Directory Domain Services, the core service used by organizations to manage users, computers, and network permissions. An attacker could exploit this flaw over the network to gain unauthorized control over the domain controller. This could lead to a total compromise of the corporate identity infrastructure, allowing for data theft or widespread service disruption.
Technical details
A heap-based buffer overflow (CWE-122) exists in Microsoft Active Directory Domain Services (AD DS). The vulnerability is triggered when the service improperly handles specially crafted network requests, leading to memory corruption. An unauthenticated attacker can exploit this over the network to achieve remote code execution (RCE) in the context of the SYSTEM account. While the attack vector is network-based and requires no user interaction, the CVSS complexity is rated as High, suggesting specific timing or environmental conditions may be required for successful exploitation. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 All versions
- Microsoft Active Directory Domain Services
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory