Windows Active Directory Denial of Service Vulnerability

Plan PatchCVSS 7.5CVE-2026-54119Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Loop with unreachable exit condition in Windows Active Directory allows an unauthorized attacker to deny service over a network.

What this means
What could happen
An attacker can send a specially crafted network request to Windows Active Directory, causing it to enter an infinite loop that makes domain authentication and directory services unavailable. This would prevent users and systems from logging in or communicating with domain controllers, disrupting plant operations dependent on networked access control.
Who's at risk
Water utilities, electric utilities, and other critical infrastructure operators using Windows Server as domain controllers or Windows 10/11 client systems for engineering workstations, SCADA front-end systems, or administrative access. The vulnerability affects any organization relying on Active Directory for access control and authentication.
How it could be exploited
An attacker with network access to a Windows domain controller running a vulnerable version sends a specially crafted Active Directory request that triggers the infinite loop condition. No user interaction or authentication is required; the attack succeeds when the request reaches the AD service.
Prerequisites
  • Network access to Active Directory on port 389 (LDAP) or 636 (LDAPS)
  • Target running vulnerable Windows Server or Windows 10/11 version with unpatched Active Directory
Remotely exploitableNo authentication requiredLow complexityAffects domain services and authenticationHigh availability impact
Exploitability
Some exploitation risk — EPSS score 1.2%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/4
Do now
0/1
WORKAROUNDRestrict network access to Active Directory ports (389 LDAP, 636 LDAPS) to only authorized domain-joined systems and administrative networks
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXApply July 2026 security update to all Windows Server 2016, 2019, 2022, and 2025 systems
All products
HOTFIXApply July 2026 security update to all Windows 10 and Windows 11 systems
Long-term hardening
0/1
HARDENINGSegment domain controllers on a dedicated network with firewall rules limiting LDAP/LDAPS traffic to internal subnets only
API: /api/v1/advisories/099321b9-f162-4458-92b4-827443b5ecb5

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Active Directory Denial of Service Vulnerability | CVSS 7.5 - OTPulse