Impact
The vulnerability arises from improper neutralization of special elements used in a command within Windows Active Directory services. This leads to a command injection flaw that permits an attacker to execute arbitrary commands. The impact is the potential compromise of confidentiality, integrity, and availability of domain controllers and any systems bound to them, as exploitable code could be run with local system privileges on the targeted host.
Affected Systems
The affected products include multiple Microsoft Windows clients and servers: Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including their Server Core installations. Version details are provided in the vendor product list but not in the supplied CNA affected-version field.
Risk and Exploitability
The CVSS score of 8.8 denotes high severity, and although an EPSS score is not available, the absence of a KEV listing indicates this is not a currently documented exploited vulnerability. Based on the description, the likely attack vector is a network‑based approach targeting Domain Services. An attacker would need to send a crafted request that triggers the vulnerable command injection, potentially requiring no credentials or only minimal domain privileges. Successful exploitation would grant the attacker the ability to execute code with the highest privileges on the victim host, enabling full system compromise.
OpenCVE Enrichment