Impact
The vulnerability is a use‑after‑free flaw in Active Directory Domain Services that permits an authorized attacker to execute arbitrary code on the target system via the network. The flaw allows the attacker to hijack a deallocated memory reference, which can be leveraged to trigger code execution in the context of the Active Directory service. Because code can run with the privileges of the domain service, this can lead to full compromise of the domain controller and the entire domain.
Affected Systems
The flaw affects Microsoft Windows 10, starting with version 1607 through 22H2, Windows 11 from 23H2 through 26H1, and a range of Windows Server editions—including Server 2012, 2012 R2, 2016, 2019, 2022, and 2025—across both full and server‑core installations, as surfaced in the CNA product list.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact and moderate exploitability. EPSS is not available, and the weakness is not yet listed in the CISA KEV catalog, but the possibility for remote code execution on a domain controller remains a serious threat. An attacker with valid domain credentials or a privileged account can initiate the exploitation over the network, potentially gaining escalated control of the domain. Cybersecurity teams should treat this as a high‑priority issue until the identified patch is deployed.
OpenCVE Enrichment