Executive brief
Active Directory Domain Services (AD DS) is the core authentication and directory service for Windows enterprise networks. A use-after-free vulnerability allows an unauthenticated attacker on the network to execute arbitrary code with system privileges, potentially compromising an entire organization's identity infrastructure and enabling lateral movement across all connected systems.
Technical details
This is a use-after-free vulnerability in Active Directory Domain Services that allows memory corruption. The flaw can be triggered remotely over the network without authentication, permitting an attacker to execute arbitrary code with elevated privileges. The vulnerability exists in a core component of AD DS responsible for processing network requests. No patch availability information is currently available in the advisory; organizations should monitor Microsoft security updates for remediation.
Affected products
- Microsoft Active Directory Domain Services
Timeline
- 2026-09-08: disclosed