Windows Active Directory Domain Services Remote Code Execution Vulnerability

Plan PatchCVSS 7.5CVE-2026-62813Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

A use-after-free vulnerability in Active Directory Domain Services allows an authorized attacker with valid domain credentials to execute arbitrary code over the network on affected Windows systems. The vulnerability requires the attacker to send a specially crafted network request to the Active Directory component, allowing code execution with SYSTEM-level privileges.

What this means
What could happen
An attacker with valid Active Directory credentials could run arbitrary code on your domain controller or member server with SYSTEM privileges, potentially gaining full control of your IT environment and any connected operational systems.
Who's at risk
Organizations running Windows 10 (all supported versions), Windows 11 (all versions), Windows Server 2016, 2019, 2022, or 2025 should prioritize patching, particularly domain controllers and servers that host Active Directory Domain Services. This affects both IT infrastructure and any OT/ICS systems that use Windows as engineering workstations or integrated HMI/SCADA components.
How it could be exploited
An attacker with valid domain credentials sends a specially crafted network request to the Active Directory Domain Services component. This triggers a use-after-free memory vulnerability that allows the attacker to execute code with SYSTEM privileges on the target server.
Prerequisites
  • Valid Active Directory user credentials (domain user or higher)
  • Network access to the target Windows Server or Windows 10/11 domain member on port 389 (LDAP) or 636 (LDAPS)
  • Target must be running one of the affected Windows/Windows Server versions
remotely exploitablerequires valid credentialsaffects core infrastructure (Active Directory)high CVSS score (7.5)
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/13
Schedule — requires maintenance window
0/12

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXUpdate Windows Server 2016 to Build 10.0.14393.9512 or later
Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33438 or later
All products
HOTFIXUpdate Windows 10 Version 1607 systems to Build 10.0.14393.9512 or later
HOTFIXUpdate Windows 10 Version 1809 systems to Build 10.0.17763.9245 or later
HOTFIXUpdate Windows 10 Version 21H2 systems to Build 10.0.19044.7725 or later
HOTFIXUpdate Windows 10 Version 22H2 systems to Build 10.0.19045.7725 or later
HOTFIXUpdate Windows 11 Version 23H2 systems to Build 10.0.22631.7582 or later
HOTFIXUpdate Windows 11 Version 24H2 systems to Build 10.0.26100.9445 or later
HOTFIXUpdate Windows 11 Version 25H2 systems to Build 10.0.26200.9445 or later
HOTFIXUpdate Windows 11 Version 26H1 systems to Build 10.0.28000.2954 or later
Long-term hardening
0/1
HARDENINGRestrict LDAP/LDAPS network access to Active Directory servers to only authorized administrative workstations and systems that require it
API: /api/v1/advisories/d8e26dd6-5841-4dc6-8e88-9eab7fc75f04

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Active Directory Domain Services Remote Code Execution Vulnerability | CVSS 7.5 - OTPulse