Windows Active Directory Denial of Service Vulnerability
Plan PatchCVSS 7.5CVE-2026-54119Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Loop with unreachable exit condition in Windows Active Directory allows an unauthorized attacker to deny service over a network.
What this means
What could happen
An attacker can send a specially crafted network request to Windows Active Directory, causing it to enter an infinite loop that makes domain authentication and directory services unavailable. This would prevent users and systems from logging in or communicating with domain controllers, disrupting plant operations dependent on networked access control.
Who's at risk
Water utilities, electric utilities, and other critical infrastructure operators using Windows Server as domain controllers or Windows 10/11 client systems for engineering workstations, SCADA front-end systems, or administrative access. The vulnerability affects any organization relying on Active Directory for access control and authentication.
How it could be exploited
An attacker with network access to a Windows domain controller running a vulnerable version sends a specially crafted Active Directory request that triggers the infinite loop condition. No user interaction or authentication is required; the attack succeeds when the request reaches the AD service.
Prerequisites
- Network access to Active Directory on port 389 (LDAP) or 636 (LDAPS)
- Target running vulnerable Windows Server or Windows 10/11 version with unpatched Active Directory
Remotely exploitableNo authentication requiredLow complexityAffects domain services and authenticationHigh availability impact
Exploitability
Some exploitation risk — EPSS score 1.2%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/4
Do now
0/1WORKAROUNDRestrict network access to Active Directory ports (389 LDAP, 636 LDAPS) to only authorized domain-joined systems and administrative networks
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXApply July 2026 security update to all Windows Server 2016, 2019, 2022, and 2025 systems
All products
HOTFIXApply July 2026 security update to all Windows 10 and Windows 11 systems
Long-term hardening
0/1HARDENINGSegment domain controllers on a dedicated network with firewall rules limiting LDAP/LDAPS traffic to internal subnets only
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/099321b9-f162-4458-92b4-827443b5ecb5Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.