Description
Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.
Published: 2026-07-14
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an out‑of‑bounds read (CWE‑125) in the Windows Active Directory component. An attacker who already possesses authorized network access can trigger a crash or hang of the AD service, leading to a denial of service for users and applications that rely on directory functionality. The flaw has no known impact on confidentiality or integrity; its primary effect is to render the service unavailable.

Affected Systems

Microsoft Windows 10 Version 21H2 and 22H2 (32‑bit and 64‑bit), Microsoft Windows 11 Versions 24H2, 25H2, and 26H1 (ARM64 and 64‑bit as noted), and Microsoft Windows Server 2022 and Server 2025, including Server Core installations. These releases are impacted according to the vendor’s advisory.

Risk and Exploitability

With a CVSS score of 7.1 the issue is classified as medium severity. An EPSS score of less than 1% indicates that exploitation is unlikely at the current time. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread active exploitation. Because the flaw requires an attacker with already authorized privileges within the domain, the likely attack vector is an internal or compromised network user. Organizations should treat this as a medium‑severity risk that can be mitigated through patching and by limiting privileged account use.

Generated by OpenCVE AI on July 31, 2026 at 07:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update that patches the out‑of‑bounds read weakness (CWE‑125) in the Windows Active Directory component.
  • Restrict the use of privileged Active Directory accounts to reduce the scope of an authorized attacker.
  • Monitor Active Directory service availability and network logs for signs of denial‑of‑service activity.

Generated by OpenCVE AI on July 31, 2026 at 07:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 17 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.
Title Active Directory Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-125
CPEs cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 21h2 Windows 10 22h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:56:40.897Z

Reserved: 2026-06-05T14:35:07.080Z

Link: CVE-2026-50682

cve-icon Vulnrichment

Updated: 2026-07-14T19:21:14.385Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T07:30:04Z

Weaknesses