Windows Active Directory Domain Services Denial of Service Vulnerability
Plan PatchCVSS 7.5CVE-2026-69809Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Missing release of memory after effective lifetime in Active Directory Domain Services allows an unauthorized attacker to deny service over a network. This is a memory leak vulnerability in AD DS that can be triggered remotely without authentication.
What this means
What could happen
An attacker could cause Active Directory Domain Services to become unavailable by triggering a memory leak, making domain authentication and group policy distribution fail. This would prevent users from logging in and could disrupt automated processes that depend on domain connectivity.
Who's at risk
This affects organizations running Windows Server 2022, Windows Server 2025, or Windows 11 as domain controllers or with Active Directory Domain Services. Any site that uses AD for authentication, group policy, or resource management depends on this service—which includes most municipal IT environments and all utilities using centralized Windows authentication.
How it could be exploited
An attacker with network access to your domain controllers can send specially crafted requests over the network to trigger the memory leak in AD DS. By repeating these requests, they exhaust available memory on the domain controller until it stops responding to authentication and domain management requests.
Prerequisites
- Network access to domain controller on Active Directory ports (typically TCP 389, 636, 3268, 3269)
- No authentication required
remotely exploitableno authentication requiredlow complexityaffects critical directory servicescan disrupt authentication infrastructure
Exploitability
Some exploitation risk — EPSS score 1.1%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/5
Do now
0/1WORKAROUNDRestrict network access to Active Directory ports (389, 636, 3268, 3269) on domain controllers to only authorized networks and clients
Schedule — requires maintenance window
0/3Patching may require device reboot — plan for process interruption
Windows Server 2022
HOTFIXApply September 2026 Windows security update to Windows Server 2022 domain controllers (Build 10.0.20348.5622 or later)
Windows Server 2025
HOTFIXApply September 2026 Windows security update to Windows Server 2025 domain controllers (Build 10.0.26100.33438 or later)
All products
HOTFIXApply September 2026 Windows security update to Windows 11 systems running Active Directory Domain Services
Long-term hardening
0/1HARDENINGMonitor domain controller memory usage and availability to detect unexpected resource exhaustion; implement alerting for abnormal memory consumption patterns
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/0e6052d1-1a4e-452b-885f-7130b8eb3536Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.