Impact
The vulnerability is a use‑after‑free in the Active Directory Certificate Services component of Windows, allowing an attacker with authorized access to execute arbitrary code on the affected system over a network. This grants the attacker full control over the target host, enabling data exfiltration, persistence, or further lateral movement. The weakness is reflected by the CWE‑416 identifier.
Affected Systems
Affected products include Microsoft Windows 10 released as Version 1607 and 1809, and a range of Windows Server operating systems from Server 2012 through Server 2025, including both stable and Server Core installations. Systems that have not received the latest security updates for these versions are vulnerable.
Risk and Exploitability
The CVSS v3.1 score is 8.8, indicating high severity. The EPSS score is < 1%, indicating a very low probability of exploitation at this time, though there are no reports of widespread attacks. The vulnerability is not listed in CISA’s KEV catalog. A typical exploit requires the attacker to have network access to the AD CS service and legitimate credentials or sufficient privileges to send a crafted request. Once the request triggers the use‑after‑free, arbitrary code executes with the privileges of the AD CS service.
OpenCVE Enrichment