Executive brief
A security vulnerability has been identified in Microsoft Active Directory Domain Services, the core service used by organizations to manage users, computers, and network permissions. An attacker with basic user credentials could exploit this flaw to take control of the domain controller or disrupt network operations. This could lead to a total compromise of the organization's identity management system and unauthorized access to sensitive data.
Technical details
A heap-based buffer overflow (CWE-122) exists within Microsoft Active Directory Domain Services (AD DS). The vulnerability is reachable over the network and requires low-privileged authentication (PR:L). By sending specially crafted requests to an affected domain controller, an attacker can trigger the overflow to achieve remote code execution (RCE) in the context of the service. This affects multiple versions of Windows and Windows Server, including Windows 10, Windows 11, and Windows Server 2012. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 All versions
- Microsoft Active Directory Domain Services
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory