Executive brief
Active Directory Domain Services is a critical infrastructure component used by organizations to manage user identities and access across networks. A use-after-free vulnerability allows an authenticated attacker to execute arbitrary code on domain controllers over the network, potentially compromising the entire organization's identity and access management system.
Technical details
A use-after-free vulnerability exists in Microsoft Active Directory Domain Services that can be exploited by an authorized network attacker to achieve remote code execution. The vulnerability requires prior authentication to the system. An attacker with valid credentials can craft a malicious network request that triggers the use-after-free condition, leading to arbitrary code execution in the context of the ADDS service. This could allow an authenticated attacker to escalate privileges, compromise domain controllers, or propagate laterally throughout an Active Directory environment.
Affected products
- Microsoft Active Directory Domain Services
Timeline
- 2026-09-08: disclosed