Windows Active Directory Domain Services Remote Code Execution Vulnerability
Plan PatchCVSS 8.8CVE-2026-49178Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.
What this means
What could happen
An attacker with domain user credentials could execute arbitrary code on your domain controller or domain-joined servers, potentially compromising your entire Active Directory infrastructure and allowing them to modify user accounts, permissions, or plant persistent backdoors.
Who's at risk
This affects IT administrators and domain controller operators running Windows Server 2016, 2019, 2022, or 2025, as well as organizations with domain-joined Windows 10 or Windows 11 workstations. Any system with Active Directory Domain Services is at risk if an insider or compromised user account exists on your network.
How it could be exploited
An attacker with valid domain credentials (standard user or admin) connects to a domain controller or domain-joined server over the network, sends a specially crafted request to the Active Directory Domain Services service, which triggers the buffer overflow and executes the attacker's code with system privileges.
Prerequisites
- Valid domain user credentials (standard user account minimum)
- Network access to domain controller or domain-joined server on port 389 (LDAP) or 636 (LDAPS)
- Target system running affected Windows Server or Windows 10/11 version
Remotely exploitableRequires domain user authenticationAffects critical Active Directory infrastructureNo authentication required from network (only domain credentials needed)High CVSS score (8.8)
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict LDAP access (ports 389 and 636) to domain controllers to only authorized directory servers and administrative workstations; block access from untrusted networks
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXInstall the July 2026 Windows security update for your Windows Server version (Build 10.0.17763.9020 for Server 2019, 10.0.20348.5386 for Server 2022, 10.0.26100.33158 for Server 2025, or 10.0.14393.9339 for Server 2016)
Long-term hardening
0/1HARDENINGReview and audit domain user accounts with elevated privileges to detect and remove unnecessary administrator accounts
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/fd76db62-c8e0-46d1-9eea-04fa5f1db543Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.