Executive brief
A security vulnerability has been identified in Microsoft Active Directory Domain Services, the core service used by organizations to manage users, computers, and network permissions. An authorized user on the network could exploit this flaw to crash the service, leading to a denial-of-service condition. This would prevent users from logging in or accessing shared network resources, potentially disrupting business operations.
Technical details
A NULL pointer dereference (CWE-476) exists within Microsoft Active Directory Domain Services. An attacker with low-privileged domain credentials can trigger this vulnerability over the network without user interaction. Successful exploitation causes the affected service to crash, resulting in a denial-of-service (DoS) for authentication and directory lookup functions. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server 2012. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 All editions including Server Core
- Microsoft Active Directory Domain Services
Timeline
- 2026-07-14: advisory: Initial advisory published by Microsoft and NVD
- 2026-07-14: patched: Security updates made available via Microsoft Security Update Guide