Windows Active Directory Domain Services Denial of Service Vulnerability

Plan PatchCVSS 7.5CVE-2026-69809Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Missing release of memory after effective lifetime in Active Directory Domain Services allows an unauthorized attacker to deny service over a network. This is a memory leak vulnerability in AD DS that can be triggered remotely without authentication.

What this means
What could happen
An attacker could cause Active Directory Domain Services to become unavailable by triggering a memory leak, making domain authentication and group policy distribution fail. This would prevent users from logging in and could disrupt automated processes that depend on domain connectivity.
Who's at risk
This affects organizations running Windows Server 2022, Windows Server 2025, or Windows 11 as domain controllers or with Active Directory Domain Services. Any site that uses AD for authentication, group policy, or resource management depends on this service—which includes most municipal IT environments and all utilities using centralized Windows authentication.
How it could be exploited
An attacker with network access to your domain controllers can send specially crafted requests over the network to trigger the memory leak in AD DS. By repeating these requests, they exhaust available memory on the domain controller until it stops responding to authentication and domain management requests.
Prerequisites
  • Network access to domain controller on Active Directory ports (typically TCP 389, 636, 3268, 3269)
  • No authentication required
remotely exploitableno authentication requiredlow complexityaffects critical directory servicescan disrupt authentication infrastructure
Exploitability
Some exploitation risk — EPSS score 1.1%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.9445
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.9445
Windows 11 Version 23H2 for ARM64-based SystemsAll versionsBuild 10.0.22631.7582
Windows 11 Version 23H2 for x64-based SystemsAll versionsBuild 10.0.22631.7582
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26100.9445
Remediation & Mitigation
0/5
Do now
0/1
WORKAROUNDRestrict network access to Active Directory ports (389, 636, 3268, 3269) on domain controllers to only authorized networks and clients
Schedule — requires maintenance window
0/3

Patching may require device reboot — plan for process interruption

Windows Server 2022
HOTFIXApply September 2026 Windows security update to Windows Server 2022 domain controllers (Build 10.0.20348.5622 or later)
Windows Server 2025
HOTFIXApply September 2026 Windows security update to Windows Server 2025 domain controllers (Build 10.0.26100.33438 or later)
All products
HOTFIXApply September 2026 Windows security update to Windows 11 systems running Active Directory Domain Services
Long-term hardening
0/1
HARDENINGMonitor domain controller memory usage and availability to detect unexpected resource exhaustion; implement alerting for abnormal memory consumption patterns
API: /api/v1/advisories/0e6052d1-1a4e-452b-885f-7130b8eb3536

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Active Directory Domain Services Denial of Service Vulnerability | CVSS 7.5 - OTPulse