Impact
Use after free in Active Directory Domain Services enables an unauthenticated attacker to execute arbitrary code over the network, resulting in remote code execution. The vulnerability flows from improper use of freed memory, allowing malicious payload delivery to gain control of a domain controller. This loss of secrecy, integrity, and availability can lead to full domain compromise.
Affected Systems
The flaw affects Microsoft Windows versions 10 (1607 to 22H2) and Windows 11 (23H2 to 26H1) across x86, x64, and arm64 architectures, as well as Windows Server 2012 through 2025, including both full and Server Core installations, in both 32‑bit and 64‑bit flavors where applicable.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, but EPSS data is currently unavailable, so the exact exploitation probability cannot be quantified from the supplied data. The vulnerability is not listed in the CISA KEV catalog, so known exploitation in the wild has not been reported. The likely attack vector is remote, using Active Directory traffic such as LDAP, Kerberos, or RPC, making domain controllers a high-value target for attackers who can reach the network segment where the AD service is exposed. Given the scope and the critical role of Active Directory, the risk to network security remains high.
OpenCVE Enrichment