Impact
A memory release flaw in Active Directory Domain Services allows an attacker without proper authorization to trigger a denial‑of‑service condition over a network. The vulnerability stems from a missing deallocation after the object's effective lifetime, which can cause the AD service to become unresponsive when the faulty memory is accessed repeatedly. The impact is limited to service availability; it does not directly expose data or grant elevated privileges.
Affected Systems
Microsoft Windows products are affected: Windows 11 versions 23H2, 24H2, 25H2, 26H1 and Windows Server 2022, 2025 (including Server Core installations).
Risk and Exploitability
The CVSS score of 7.5 places this issue in the high severity range. The EPSS score is 1% and it is not yet in the CISA KEV catalog, indicating a currently moderate likelihood of exploitation. The attack requires network access to an Active Directory Domain Services instance and does not require privileged credentials; an unauthenticated attacker can trigger the flaw by sending crafted traffic to the AD service endpoint. Once activated, the service becomes unavailable to legitimate users until a restart or remediation occurs.
OpenCVE Enrichment