Junglewise Threat Intelligence

CVE-2026-69524: Microsoft Active Directory Domain Services use-after-free

CVE-2026-69524 · Severity: high · CVSS 8.1 · Published 2026-09-08

Executive brief

Active Directory Domain Services (AD DS) is the core authentication and directory service for Windows enterprise networks. A use-after-free vulnerability allows an unauthenticated attacker on the network to execute arbitrary code with system privileges, potentially compromising an entire organization's identity infrastructure and enabling lateral movement across all connected systems.

Technical details

This is a use-after-free vulnerability in Active Directory Domain Services that allows memory corruption. The flaw can be triggered remotely over the network without authentication, permitting an attacker to execute arbitrary code with elevated privileges. The vulnerability exists in a core component of AD DS responsible for processing network requests. No patch availability information is currently available in the advisory; organizations should monitor Microsoft security updates for remediation.

Affected products

  • Microsoft Active Directory Domain Services

Timeline

  • 2026-09-08: disclosed

References

Related threats