Impact
A use‑after‑free condition was discovered in Active Directory Domain Services that permits an unauthorized attacker to execute arbitrary code when communicating over the network. The vulnerability arises from the service’s improper handling of memory after a previously freed object is accessed, allowing the attacker to control execution flow once the malicious input is sent. Successful exploitation results in full compromise of the affected AD DS instance, potentially giving the attacker administrative privileges on the domain.
Affected Systems
Microsoft Windows 10 builds 1607, 1809, 21H2, 22H2, Windows 11 builds 23H2, 24H2, 25H2, 26H1, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 releases (both full and Server Core installations). The affected binaries are part of the standard Active Directory Domain Services role on these operating systems.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, yet the EPSS score is currently unavailable, making it unclear how frequently this vulnerability might be exploited in the wild. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed or widespread exploitation at present. Nonetheless, the nature of the flaw—remote code execution—confers a broad attack surface for adversaries that can reach the AD DS traffic, likely over standard LDAP or Kerberos ports. Given the privileged impact, organizations should treat this as a critical threat.
OpenCVE Enrichment