Windows Active Directory Domain Services Denial of Service Vulnerability
MonitorCVSS 6.5CVE-2026-62762Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A null pointer dereference in Windows Active Directory Domain Services allows an authenticated attacker to cause a denial of service condition by sending a malicious network request. When exploited, the AD service crashes, rendering domain authentication unavailable until the service is manually restarted. The attacker must have valid domain credentials and network access to a domain controller.
What this means
What could happen
An authenticated user could send a malicious network request to Active Directory that causes the AD service to crash, making the domain unavailable for authentication and operations until the service restarts. This would prevent users and devices from logging in and accessing network resources.
Who's at risk
This affects domain controllers running Windows Server 2016, 2019, 2022, or 2025, as well as Windows 10 and Windows 11 systems that host Active Directory components. Any organization running on-premises Active Directory should prioritize updating domain controllers. This is most critical for utilities and water authorities that rely on AD for network authentication and access control to SCADA/HMI systems.
How it could be exploited
An attacker with valid domain credentials sends a crafted network request targeting a null pointer in Active Directory Domain Services. The AD service crashes, triggering a denial of service. No special tools or additional vulnerabilities are required—just network access to the domain controller and valid AD credentials.
Prerequisites
- Network access to domain controller (port 389 LDAP or 636 LDAPS)
- Valid Active Directory user credentials
- Authenticated AD session
Remotely exploitableRequires authenticationActively exploited: NoAffects identity and authentication services
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict LDAP and LDAPS (ports 389, 636) access to domain controllers to only authorized administrative networks and trusted sites
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply Microsoft's September 2026 security updates to all domain controllers and systems running Active Directory Domain Services
Long-term hardening
0/1HARDENINGMonitor Active Directory service health and configure alerts for unexpected service restarts or crashes
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/7c96cd4a-d701-433f-a5e9-76492ea6fc41Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.