Junglewise Threat Intelligence

CVE-2026-62813: Microsoft Active Directory Domain Services use-after-free remote code execution

CVE-2026-62813 · Severity: high · CVSS 7.5 · Published 2026-09-08

Executive brief

Active Directory Domain Services is a critical infrastructure component used by organizations to manage user identities and access across networks. A use-after-free vulnerability allows an authenticated attacker to execute arbitrary code on domain controllers over the network, potentially compromising the entire organization's identity and access management system.

Technical details

A use-after-free vulnerability exists in Microsoft Active Directory Domain Services that can be exploited by an authorized network attacker to achieve remote code execution. The vulnerability requires prior authentication to the system. An attacker with valid credentials can craft a malicious network request that triggers the use-after-free condition, leading to arbitrary code execution in the context of the ADDS service. This could allow an authenticated attacker to escalate privileges, compromise domain controllers, or propagate laterally throughout an Active Directory environment.

Affected products

  • Microsoft Active Directory Domain Services

Timeline

  • 2026-09-08: disclosed

References

Related threats