Junglewise Threat Intelligence

CVE-2026-69712: Microsoft Windows Key Distribution Center use-after-free

CVE-2026-69712 · Severity: high · CVSS 8.8 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

The Windows Key Distribution Center (KDC) is a critical component of Active Directory that issues authentication tickets to domain computers and users. A use-after-free vulnerability allows an authorized attacker on the network to execute arbitrary code with system privileges, potentially compromising domain security and gaining control of infrastructure.

Technical details

This is a use-after-free vulnerability in the Windows Key Distribution Center (KDC), a core component of Kerberos authentication in Active Directory environments. The vulnerability requires the attacker to be authenticated and have network access to the KDC service (typically port 88). Exploitation allows remote code execution with SYSTEM privileges. The attack vector is network-based and does not require additional user interaction beyond initial authentication credentials. Microsoft has released patches to address this issue; administrators should apply security updates immediately to all affected domain controllers.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats