Windows Active Directory Domain Services Denial of Service Vulnerability
MonitorCVSS 6.5CVE-2026-57976Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A null pointer dereference vulnerability in Active Directory Domain Services allows an authorized attacker to cause a denial of service by sending a specially crafted network request. The vulnerability affects all supported versions of Windows Server 2016, 2019, 2022, and 2025, as well as Windows 10 and 11 systems participating in Active Directory domains. Exploitation requires valid domain user credentials and network access to the LDAP service on domain controllers.
What this means
What could happen
An attacker with valid domain credentials could crash or hang your Active Directory Domain Services, making domain services unavailable and disrupting authentication, user login, and access to networked systems and equipment.
Who's at risk
Organizations running Windows Server 2016, 2019, 2022, or 2025 as domain controllers, and Windows 10 or 11 systems that participate in Active Directory domains. This affects all utilities and plants that rely on domain authentication for access to workstations, engineering systems, and networked industrial equipment.
How it could be exploited
An attacker with valid domain user credentials sends a specially crafted network request to an Active Directory Domain Services server (port 389 LDAP or 636 LDAPS), triggering a null pointer dereference that causes the AD service to crash or become unresponsive.
Prerequisites
- Network access to port 389 (LDAP) or 636 (LDAPS) on domain controllers
- Valid domain user account credentials
remotely exploitablerequires valid credentialslow complexity attackaffects authentication infrastructure
Exploitability
Some exploitation risk — EPSS score 1.1%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict LDAP access (ports 389/TCP and 636/TCP) to domain controllers from only trusted administrative and client networks using firewall rules
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate all domain controllers and systems running Active Directory Domain Services to the July 2026 security patch for your Windows version (Build 10.0.17763.9020 for Server 2019; Build 10.0.20348.5386 for Server 2022; Build 10.0.26100.33158 for Server 2025)
Long-term hardening
0/1HARDENINGEnforce strong domain password policies and multi-factor authentication to reduce the risk of unauthorized credential access
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/ce2c9c4b-73e7-459c-a99f-6ceb070a3377Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.