Windows Active Directory Domain Services Remote Code Execution Vulnerability
Plan PatchCVSS 8.8CVE-2026-49179Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary
A command injection vulnerability in Windows Active Directory Domain Services allows an unauthorized attacker to execute code over a network. Exploitation requires network access to a domain-joined system and user interaction. The vulnerability affects Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 across multiple architectures and installation types.
What this means
What could happen
An attacker could execute arbitrary code on a Windows domain controller or domain-joined machine through Active Directory, potentially compromising domain accounts, modifying security policies, or disrupting authentication services that critical OT systems rely on.
Who's at risk
Any organization using Windows-based domain controllers or domain-joined workstations and servers, especially utilities running SCADA systems, HMIs, or engineering workstations that authenticate against Active Directory. This impacts domain management, user access, and centralized authentication that OT systems often depend on.
How it could be exploited
An attacker sends a specially crafted command through Active Directory that exploits improper handling of special characters. If a domain-joined workstation, server, or domain controller processes this input, the attacker's code runs with the privileges of the AD service or logged-in user.
Prerequisites
- Network access to a domain-joined Windows system or domain controller
- User interaction required (user must open or process a specially crafted input)
- System must be domain-joined and communicating with Active Directory
remotely exploitableaffects domain authentication infrastructurerequires user interactionimpacts OT network domain membership
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/4
Do now
0/1HARDENINGRestrict network access to domain controllers; only allow traffic from trusted domain-joined systems and administrative networks
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXPrioritize patching Windows Server 2016, 2019, 2022, and 2025 systems first as these are commonly used for domain controllers
All products
HOTFIXApply the August 2026 Windows security update to all domain controllers and domain-joined servers
Long-term hardening
0/1HARDENINGMonitor Active Directory logs for unusual command execution or authentication anomalies
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/fea929b5-49c8-4c09-a163-8666488eff0bGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.