Junglewise Threat Intelligence

CVE-2026-50366: Microsoft Active Directory Domain Services DoS via NULL pointer dereference

CVE-2026-50366 · Severity: medium · CVSS 6.5 · Published 2026-07-14

Executive brief

A vulnerability in Microsoft Active Directory Domain Services could allow an authorized user to crash the service remotely. Active Directory is the central system used by organizations to manage users, computers, and security permissions. If exploited, this could lead to a significant service outage, preventing users from logging in or accessing corporate resources.

Technical details

A NULL pointer dereference vulnerability (CWE-476) exists in Microsoft Active Directory Domain Services. An authenticated attacker with low privileges can trigger this flaw by sending a specially crafted request over the network to a domain controller. Successful exploitation causes the service to crash, resulting in a denial-of-service (DoS) condition. The vulnerability affects multiple versions of Windows and Windows Server, and Microsoft has released security updates to address the issue.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 All editions
  • Microsoft Active Directory Domain Services

Timeline

  • 2026-07-14: advisory: Initial advisory published by Microsoft and NVD.
  • 2026-07-14: patched: Security updates made available via Microsoft Security Update Guide.

References

Related threats