Description
Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.
Published: 2026-08-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free in the Active Directory Certificate Services component of Windows, allowing an attacker with authorized access to execute arbitrary code on the affected system over a network. This grants the attacker full control over the target host, enabling data exfiltration, persistence, or further lateral movement. The weakness is reflected by the CWE‑416 identifier.

Affected Systems

Affected products include Microsoft Windows 10 released as Version 1607 and 1809, and a range of Windows Server operating systems from Server 2012 through Server 2025, including both stable and Server Core installations. Systems that have not received the latest security updates for these versions are vulnerable.

Risk and Exploitability

The CVSS v3.1 score is 8.8, indicating high severity. The EPSS score is < 1%, indicating a very low probability of exploitation at this time, though there are no reports of widespread attacks. The vulnerability is not listed in CISA’s KEV catalog. A typical exploit requires the attacker to have network access to the AD CS service and legitimate credentials or sufficient privileges to send a crafted request. Once the request triggers the use‑after‑free, arbitrary code executes with the privileges of the AD CS service.

Generated by OpenCVE AI on August 12, 2026 at 16:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Windows security updates that address CVE-2026-62818.
  • Restrict network access to AD CS endpoints with firewall rules or segmentation to limit exposure.
  • If an immediate patch is not available, monitor AD CS activity and consider disabling or restricting the service until the fix is applied.

Generated by OpenCVE AI on August 12, 2026 at 16:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.
Title Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows Server 2012 Windows Server 2012 R2 Windows Server 2016 Windows Server 2019 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-12T14:47:44.863Z

Reserved: 2026-07-14T21:10:38.081Z

Link: CVE-2026-62818

cve-icon Vulnrichment

Updated: 2026-08-12T13:44:02.056Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-11T17:18:35.797

Modified: 2026-08-12T14:18:22.233

Link: CVE-2026-62818

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T16:45:05Z

Weaknesses