Windows Active Directory Domain Services Denial of Service Vulnerability

MonitorCVSS 6.5CVE-2026-62762Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A null pointer dereference in Windows Active Directory Domain Services allows an authenticated attacker to cause a denial of service condition by sending a malicious network request. When exploited, the AD service crashes, rendering domain authentication unavailable until the service is manually restarted. The attacker must have valid domain credentials and network access to a domain controller.

What this means
What could happen
An authenticated user could send a malicious network request to Active Directory that causes the AD service to crash, making the domain unavailable for authentication and operations until the service restarts. This would prevent users and devices from logging in and accessing network resources.
Who's at risk
This affects domain controllers running Windows Server 2016, 2019, 2022, or 2025, as well as Windows 10 and Windows 11 systems that host Active Directory components. Any organization running on-premises Active Directory should prioritize updating domain controllers. This is most critical for utilities and water authorities that rely on AD for network authentication and access control to SCADA/HMI systems.
How it could be exploited
An attacker with valid domain credentials sends a crafted network request targeting a null pointer in Active Directory Domain Services. The AD service crashes, triggering a denial of service. No special tools or additional vulnerabilities are required—just network access to the domain controller and valid AD credentials.
Prerequisites
  • Network access to domain controller (port 389 LDAP or 636 LDAPS)
  • Valid Active Directory user credentials
  • Authenticated AD session
Remotely exploitableRequires authenticationActively exploited: NoAffects identity and authentication services
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict LDAP and LDAPS (ports 389, 636) access to domain controllers to only authorized administrative networks and trusted sites
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply Microsoft's September 2026 security updates to all domain controllers and systems running Active Directory Domain Services
Long-term hardening
0/1
HARDENINGMonitor Active Directory service health and configure alerts for unexpected service restarts or crashes
API: /api/v1/advisories/7c96cd4a-d701-433f-a5e9-76492ea6fc41

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.