Description
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a null pointer dereference in Windows Active Directory Domain Services that can cause the service to terminate unexpectedly. The effect is a denial of service to domain controller functionality, which can disrupt authentication, authorization, and directory queries for users and applications. The flaw is a classic memory handling error (CWE‑476) that can be triggered by input that the service fails to validate before dereferencing a pointer, leading to a crash. The official CVE description confirms that an attacker who already has authorization within the domain can exploit this defect over the network to bring down the service.

Affected Systems

The flaw affects Windows 10 and Windows 11 clients from versions 1607 through 26H1, as well as a range of Windows Server editions from 2012 to 2025, including server core installations. All listed Windows operating systems that run Active Directory Domain Services are therefore susceptible until the Microsoft patch is applied.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity. Exploit probability data (EPSS) is not available, and the vulnerability is not listed in the CISA KEV catalog. Given that the flaw requires authorized domain access and is delivered over the network, it is plausible that an attacker with legitimate credentials or one who has compromised a trusted account could trigger it. The risk is moderate, but if the domain controller experiences repeated crashes, it could result in significant downtime for an organization’s identity services.

Generated by OpenCVE AI on September 8, 2026 at 18:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Windows security updates, including the Microsoft update referenced in the MSRC link for CVE-2026-62762.
  • Restrict administrative privileges on domain controllers so that only trusted accounts can perform privileged actions and consider limiting network exposure of AD services to necessary hosts.
  • Enable detailed event logging on domain controllers and monitor for repeated restart or crash events that may indicate exploitation attempts.

Generated by OpenCVE AI on September 8, 2026 at 18:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
Title Windows Active Directory Domain Services Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-476
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows 10 21h2 Windows 10 22h2 Windows 11 23h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2012 Windows Server 2012 R2 Windows Server 2016 Windows Server 2019 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T18:34:33.034Z

Reserved: 2026-07-14T21:01:21.824Z

Link: CVE-2026-62762

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:17:59.347

Modified: 2026-09-08T18:38:46.007

Link: CVE-2026-62762

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T19:00:13Z

Weaknesses