Windows Active Directory Domain Services Remote Code Execution Vulnerability

Plan PatchCVSS 8.8CVE-2026-49179Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

A command injection vulnerability in Windows Active Directory Domain Services allows an unauthorized attacker to execute code over a network. Exploitation requires network access to a domain-joined system and user interaction. The vulnerability affects Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 across multiple architectures and installation types.

What this means
What could happen
An attacker could execute arbitrary code on a Windows domain controller or domain-joined machine through Active Directory, potentially compromising domain accounts, modifying security policies, or disrupting authentication services that critical OT systems rely on.
Who's at risk
Any organization using Windows-based domain controllers or domain-joined workstations and servers, especially utilities running SCADA systems, HMIs, or engineering workstations that authenticate against Active Directory. This impacts domain management, user access, and centralized authentication that OT systems often depend on.
How it could be exploited
An attacker sends a specially crafted command through Active Directory that exploits improper handling of special characters. If a domain-joined workstation, server, or domain controller processes this input, the attacker's code runs with the privileges of the AD service or logged-in user.
Prerequisites
  • Network access to a domain-joined Windows system or domain controller
  • User interaction required (user must open or process a specially crafted input)
  • System must be domain-joined and communicating with Active Directory
remotely exploitableaffects domain authentication infrastructurerequires user interactionimpacts OT network domain membership
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Remediation & Mitigation
0/4
Do now
0/1
HARDENINGRestrict network access to domain controllers; only allow traffic from trusted domain-joined systems and administrative networks
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXPrioritize patching Windows Server 2016, 2019, 2022, and 2025 systems first as these are commonly used for domain controllers
All products
HOTFIXApply the August 2026 Windows security update to all domain controllers and domain-joined servers
Long-term hardening
0/1
HARDENINGMonitor Active Directory logs for unusual command execution or authentication anomalies
API: /api/v1/advisories/fea929b5-49c8-4c09-a163-8666488eff0b

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Active Directory Domain Services Remote Code Execution Vulnerability | CVSS 8.8 - OTPulse