Junglewise Threat Intelligence

CVE-2026-69359: Microsoft Active Directory Domain Services heap buffer overflow

CVE-2026-69359 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Active Directory Domain Services is the core directory service used by Windows networks to manage user accounts, computers, and security policies. A heap buffer overflow vulnerability allows a user with local authentication to escalate their privileges on an affected domain controller, potentially granting administrative access to the entire network infrastructure.

Technical details

A heap-based buffer overflow exists in Active Directory Domain Services that can be triggered by an authenticated local attacker. The vulnerability allows an attacker with valid credentials on a domain controller to overflow a heap buffer, leading to memory corruption and privilege escalation to SYSTEM or higher privileges. This is a local attack vector requiring prior authentication or local system access. The attacker must already have credentials or local access to execute the vulnerability; network-based exploitation from unauthenticated remote users is not possible. Microsoft has issued security updates to address this vulnerability.

Affected products

  • Microsoft Active Directory Domain Services <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats