Junglewise Threat Intelligence

CVE-2026-84001: Microsoft Windows Key Distribution Center out-of-bounds read

CVE-2026-84001 · Severity: high · CVSS 7.5 · Published 2026-09-08

Executive brief

The Windows Key Distribution Center (KDC) is a critical authentication service that manages Kerberos ticket generation and validation in enterprise networks. An out-of-bounds memory read vulnerability in this service allows an unauthenticated remote attacker to crash the KDC, disrupting authentication services across the domain and potentially preventing legitimate users from accessing network resources.

Technical details

An out-of-bounds read vulnerability exists in the Windows Key Distribution Center, a core component of the Kerberos authentication system. The vulnerability can be triggered by sending specially crafted network packets to the KDC service, requiring no authentication or user interaction. Exploitation results in denial of service through service crash or hang. The vulnerability is network-reachable and affects enterprise environments relying on Kerberos for domain authentication.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats