Active Directory Denial of Service Vulnerability

Plan PatchCVSS 7.1CVE-2026-50682Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Out-of-bounds read vulnerability in Windows Active Directory allows an authenticated attacker to cause a denial of service by crashing the Active Directory service on domain controllers. Exploitation requires valid AD credentials and network access to a domain controller.

What this means
What could happen
An authenticated attacker on your network could crash Active Directory, preventing users from logging in or accessing networked resources and potentially disrupting automated processes that depend on AD authentication.
Who's at risk
Organizations running Windows Server 2022, Windows Server 2025, or Windows 10/11 as domain controllers or member servers. This affects any business that relies on Active Directory for user authentication, including utilities, manufacturing facilities, and buildings automation systems that depend on AD for access control and automated process authentication.
How it could be exploited
An attacker with valid Active Directory credentials sends a specially crafted network request to a domain controller, triggering an out-of-bounds memory read that causes the Active Directory service to stop responding. This requires the attacker to already have network access and valid credentials (such as a compromised employee account or service account).
Prerequisites
  • Valid Active Directory credentials (user or service account)
  • Network access to a domain controller on port 389 (LDAP) or 636 (LDAPS)
  • Authenticated session to Active Directory
Requires valid credentialsRemotely exploitableCauses denial of serviceAffects authentication infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (15)
15 with fix
ProductAffected VersionsFix Status
Windows Server 2022All versionsBuild 10.0.20348.5386
Windows 10 Version 21H2 for 32-bit SystemsAll versionsBuild 10.0.19044.7548
Windows 10 Version 21H2 for ARM64-based SystemsAll versionsBuild 10.0.19044.7548
Windows 10 Version 21H2 for x64-based SystemsAll versionsBuild 10.0.19044.7548
Windows 10 Version 22H2 for x64-based SystemsAll versionsBuild 10.0.19045.7548
Windows 10 Version 22H2 for ARM64-based SystemsAll versionsBuild 10.0.19045.7548
Windows 10 Version 22H2 for 32-bit SystemsAll versionsBuild 10.0.19045.7548
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXApply the 2026-Jul Windows security update to all domain controllers and member servers
HARDENINGRestrict network access to domain controllers to only necessary systems; implement firewall rules to limit LDAP traffic to authorized subnets
Long-term hardening
0/1
HARDENINGAudit Active Directory user and service accounts to identify and disable unused or suspicious credentials
API: /api/v1/advisories/c2eecac2-eb6a-4b63-8a75-072778434841

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Active Directory Denial of Service Vulnerability | CVSS 7.1 - OTPulse