Windows Active Directory Domain Services Remote Code Execution Vulnerability
Plan PatchCVSS 8.1CVE-2026-49164Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary
A heap-based buffer overflow vulnerability in Active Directory Domain Services allows an unauthorized attacker to execute arbitrary code on a network without authentication. The vulnerability is triggered through a malformed network request to the AD DS service. Exploitation is assessed as unlikely but possible; Microsoft recommends applying the 2026-Jul security update.
What this means
What could happen
An attacker on the network could exploit a heap buffer overflow in Active Directory Domain Services to run arbitrary code on a domain controller, potentially gaining control over user authentication, computer policies, and other critical directory functions across your entire network.
Who's at risk
This affects all organizations running Active Directory Domain Services on Windows Server 2016, 2019, 2022, or 2025, as well as Windows 10 and Windows 11 systems that are domain controllers. Any organization using a traditional Active Directory environment should prioritize patching domain controllers immediately, as compromise could affect all users and computers on the network.
How it could be exploited
An attacker sends a specially crafted network request to Active Directory Domain Services (typically port 389 LDAP or 636 LDAPS) on a domain controller. The malformed input triggers a heap buffer overflow in the service, allowing the attacker to overwrite memory and execute arbitrary code with the privileges of the AD DS service (typically SYSTEM on domain controllers).
Prerequisites
- Network access to domain controller on LDAP/LDAPS ports (389/636)
- No authentication required to trigger the vulnerability
remotely exploitableno authentication requiredaffects critical infrastructure (Active Directory)heap buffer overflow can lead to complete system compromise
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/4
Do now
0/1WORKAROUNDRestrict network access to LDAP ports (389 and 636) to only authorized domain controllers and administrative workstations from your internal network
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
HOTFIXApply the Microsoft 2026-Jul security update to all domain controllers and systems running Active Directory Domain Services
HOTFIXVerify all affected Windows versions are updated to the patched build numbers listed in the advisory
Long-term hardening
0/1HARDENINGImplement network segmentation to isolate domain controllers on a separate VLAN with strict inbound access controls
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/6693796f-3603-4c18-8baa-b59119aaf73cGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.