Executive brief
A security vulnerability exists in Windows Active Directory, the service used by organizations to manage users, computers, and network permissions. An attacker who already has a standard user account on a system can exploit a flaw in how the system verifies security certificates to gain administrative control. This could allow an unauthorized person to access sensitive data, change system settings, or disrupt business operations.
Technical details
This vulnerability (CWE-295) is caused by improper certificate validation within Windows Active Directory components. An attacker with low-privileged local access can exploit this flaw to bypass security checks and elevate their privileges to a higher level, such as SYSTEM or Administrator. The attack vector is local, meaning the attacker must already have the ability to execute code on the target system, but no user interaction is required. Microsoft has released security updates to address this issue across affected versions of Windows 10 and Windows Server (2016 through 2025).
Affected products
- Microsoft Windows 10 Version 1607 / 1809 Multiple versions prior to July 2026 updates
- Microsoft Windows Server 2016 / 2019 / 2022 / 2025 Multiple versions prior to July 2026 updates
Timeline
- 2026-07-14: disclosed: Initial disclosure by Microsoft and NVD
- 2026-07-14: advisory: MSRC advisory published