Executive brief
A security vulnerability has been identified in Microsoft Windows Active Directory, the service used to manage users and computers on a network. An attacker who already has a basic user account on a system can exploit this flaw to gain full administrative control. This could allow them to access sensitive data, install software, or disrupt critical business operations.
Technical details
This vulnerability is classified as an integer overflow or wraparound (CWE-190) which can lead to a heap-based buffer overflow (CWE-122) within Windows Active Directory. The flaw is exploitable by a local attacker with low privileges (PR:L) and requires no user interaction. By successfully exploiting this issue, an attacker can elevate their privileges to a higher level, potentially gaining full system access. Microsoft has released security updates to address this vulnerability across various versions of Windows and Windows Server.
Affected products
- Microsoft Windows 10 Version 1607 < 10.0.14393.9339
- Microsoft Windows 10 Version 1809 < 10.0.17763.9020
- Microsoft Windows 10 Version 21H2 < 10.0.19044.7548
- Microsoft Windows 10 Version 22H2 < 10.0.19045.7548
- Microsoft Windows 11 Version 24H2 < 10.0.26100.8875
- Microsoft Windows Server 2012 < 6.2.9200.26226
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory