Description
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
Published: 2026-07-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a null pointer dereference in Windows Active Directory Domain Services that can be triggered by legitimate service requests. An authorized attacker can cause the AD DS service to restart, resulting in a denial of service for domain users and clients that depend on authentication or directory services. The description does not mention exposure of confidential data or modification of system integrity; based on the wording we infer that the impact is limited to availability only.

Affected Systems

Affected devices include Microsoft Windows 10 starting with version 1607 up to 22H2, Windows 11 from 24H2 through 26H1, and Windows Server ranging from 2012 (including Core) through 2025 (including Core). The versions listed cover typical enterprise builds; any device running these operating systems that hosts AD DS is potentially impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score is under 1%, suggesting a very low probability of exploitation in the wild. This vulnerability is not listed in CISA KEV, meaning no publicly catalogued active exploits are known. While the description does not specify the privilege level required, we infer that an attacker must possess sufficient rights to interact with AD DS (for example, a domain administrator or a compromised domain account). The attack vector is therefore likely internal or from an authenticated compromised account. Because the trigger is a normal service request, an authenticated attacker with these privileges can cause an inadvertent restart of the AD DS service, disrupting availability.

Generated by OpenCVE AI on July 31, 2026 at 08:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft security update for CVE‑2026‑50366 from the official update guide.
  • Verify that Active Directory Domain Services is running in a properly secured environment; restrict privileged access to domain controllers and disable unnecessary domain roles if not needed.
  • Enable monitoring of the AD DS service status and configure alerts for unexpected restarts or denial‑of‑service events.

Generated by OpenCVE AI on July 31, 2026 at 08:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
Title Windows Active Directory Domain Services Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-476
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows 10 21h2 Windows 10 22h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2012 Windows Server 2012 R2 Windows Server 2016 Windows Server 2019 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:55:10.894Z

Reserved: 2026-06-04T18:48:26.815Z

Link: CVE-2026-50366

cve-icon Vulnrichment

Updated: 2026-07-14T20:39:57.846Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T08:30:03Z

Weaknesses