Junglewise Threat Intelligence

CVE-2026-69395: Microsoft Active Directory Certificate Services format string information disclosure

CVE-2026-69395 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Vendors: Microsoft.

Executive brief

Active Directory Certificate Services (AD CS) is a core Microsoft Windows component that manages digital certificates for enterprise authentication and encryption. A format string vulnerability in this service allows an authenticated attacker to read sensitive information from the server's memory over the network, potentially exposing credentials or internal system details.

Technical details

The vulnerability is a format string flaw in Active Directory Certificate Services that permits information disclosure. An authenticated attacker can craft malicious input containing format string specifiers to read arbitrary memory contents from the AD CS service. The attack requires network access to AD CS and valid authentication credentials. Successful exploitation allows the attacker to leak sensitive data such as credentials, encryption keys, or other confidential information stored in the service's memory. Patches are available from Microsoft.

Affected products

  • Microsoft Active Directory Certificate Services

Timeline

  • 2026-09-08: disclosed

References

Related threats