Windows Active Directory Domain Services Remote Code Execution Vulnerability

Plan PatchCVSS 8.1CVE-2026-49164Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary

A heap-based buffer overflow vulnerability in Active Directory Domain Services allows an unauthorized attacker to execute arbitrary code on a network without authentication. The vulnerability is triggered through a malformed network request to the AD DS service. Exploitation is assessed as unlikely but possible; Microsoft recommends applying the 2026-Jul security update.

What this means
What could happen
An attacker on the network could exploit a heap buffer overflow in Active Directory Domain Services to run arbitrary code on a domain controller, potentially gaining control over user authentication, computer policies, and other critical directory functions across your entire network.
Who's at risk
This affects all organizations running Active Directory Domain Services on Windows Server 2016, 2019, 2022, or 2025, as well as Windows 10 and Windows 11 systems that are domain controllers. Any organization using a traditional Active Directory environment should prioritize patching domain controllers immediately, as compromise could affect all users and computers on the network.
How it could be exploited
An attacker sends a specially crafted network request to Active Directory Domain Services (typically port 389 LDAP or 636 LDAPS) on a domain controller. The malformed input triggers a heap buffer overflow in the service, allowing the attacker to overwrite memory and execute arbitrary code with the privileges of the AD DS service (typically SYSTEM on domain controllers).
Prerequisites
  • Network access to domain controller on LDAP/LDAPS ports (389/636)
  • No authentication required to trigger the vulnerability
remotely exploitableno authentication requiredaffects critical infrastructure (Active Directory)heap buffer overflow can lead to complete system compromise
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/4
Do now
0/1
WORKAROUNDRestrict network access to LDAP ports (389 and 636) to only authorized domain controllers and administrative workstations from your internal network
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXApply the Microsoft 2026-Jul security update to all domain controllers and systems running Active Directory Domain Services
HOTFIXVerify all affected Windows versions are updated to the patched build numbers listed in the advisory
Long-term hardening
0/1
HARDENINGImplement network segmentation to isolate domain controllers on a separate VLAN with strict inbound access controls
API: /api/v1/advisories/6693796f-3603-4c18-8baa-b59119aaf73c

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.