Executive brief
Active Directory Domain Services is the core directory service used by Windows networks to manage user accounts, computers, and security policies. A heap buffer overflow vulnerability allows a user with local authentication to escalate their privileges on an affected domain controller, potentially granting administrative access to the entire network infrastructure.
Technical details
A heap-based buffer overflow exists in Active Directory Domain Services that can be triggered by an authenticated local attacker. The vulnerability allows an attacker with valid credentials on a domain controller to overflow a heap buffer, leading to memory corruption and privilege escalation to SYSTEM or higher privileges. This is a local attack vector requiring prior authentication or local system access. The attacker must already have credentials or local access to execute the vulnerability; network-based exploitation from unauthenticated remote users is not possible. Microsoft has issued security updates to address this vulnerability.
Affected products
- Microsoft Active Directory Domain Services <UNKNOWN>
Timeline
- 2026-09-08: disclosed