Executive brief
The Windows Key Distribution Center (KDC) is a critical component of Active Directory that issues authentication tickets to domain computers and users. A use-after-free vulnerability allows an authorized attacker on the network to execute arbitrary code with system privileges, potentially compromising domain security and gaining control of infrastructure.
Technical details
This is a use-after-free vulnerability in the Windows Key Distribution Center (KDC), a core component of Kerberos authentication in Active Directory environments. The vulnerability requires the attacker to be authenticated and have network access to the KDC service (typically port 88). Exploitation allows remote code execution with SYSTEM privileges. The attack vector is network-based and does not require additional user interaction beyond initial authentication credentials. Microsoft has released patches to address this issue; administrators should apply security updates immediately to all affected domain controllers.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed