Impact
A heap‑based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. The flaw is classified as CWE‑122 and can enable arbitrary code execution on the target system.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 24H2, 25H2, and 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread attacks to date. Based on the description, it is inferred that the attack vector requires network‑level access to an Active Directory Domain on or have visibility to the domain controller. The risk is therefore most pronounced for environments that expose AD services to untrusted networks.
OpenCVE Enrichment