Junglewise Threat Intelligence

CVE-2026-69809: Microsoft Active Directory Domain Services memory leak denial of service

CVE-2026-69809 · Severity: high · CVSS 7.5 · Published 2026-09-08

Executive brief

Active Directory Domain Services is a core Windows Server component that manages user identities and access control across enterprise networks. A memory leak vulnerability allows an unauthenticated attacker to exhaust server resources and cause a denial of service, disrupting directory services and potentially affecting all dependent systems and applications.

Technical details

This vulnerability is a memory leak (missing release of memory after effective lifetime) in Microsoft Active Directory Domain Services. The flaw is remotely exploitable over a network and requires no authentication or user interaction. An attacker can send crafted network requests that trigger the memory leak, causing the affected server to consume increasing amounts of memory until resources are exhausted, resulting in denial of service. The CVSS score of 7.5 reflects the high availability impact despite the network-based attack vector.

Affected products

  • Microsoft Active Directory Domain Services <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats