Description
Missing release of memory after effective lifetime in Active Directory Domain Services allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Score: 7.5 High
EPSS: 1.2% Low
KEV: No
Impact: Service Denial
Action: Assess Impact
AI Analysis

Impact

A memory release flaw in Active Directory Domain Services allows an attacker without proper authorization to trigger a denial‑of‑service condition over a network. The vulnerability stems from a missing deallocation after the object's effective lifetime, which can cause the AD service to become unresponsive when the faulty memory is accessed repeatedly. The impact is limited to service availability; it does not directly expose data or grant elevated privileges.

Affected Systems

Microsoft Windows products are affected: Windows 11 versions 23H2, 24H2, 25H2, 26H1 and Windows Server 2022, 2025 (including Server Core installations).

Risk and Exploitability

The CVSS score of 7.5 places this issue in the high severity range. The EPSS score is 1% and it is not yet in the CISA KEV catalog, indicating a currently moderate likelihood of exploitation. The attack requires network access to an Active Directory Domain Services instance and does not require privileged credentials; an unauthenticated attacker can trigger the flaw by sending crafted traffic to the AD service endpoint. Once activated, the service becomes unavailable to legitimate users until a restart or remediation occurs.

Generated by OpenCVE AI on September 9, 2026 at 20:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any security updates or patches released by Microsoft for the affected Windows versions.
  • Limit network exposure of Active Directory Domain Services by restricting traffic to trusted zones only and blocking unnecessary protocols.
  • Enable monitoring of AD service health and sudden restarts, and alert on anomalous traffic patterns to detect exploitation attempts.

Generated by OpenCVE AI on September 9, 2026 at 20:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Missing release of memory after effective lifetime in Active Directory Domain Services allows an unauthorized attacker to deny service over a network.
Title Windows Active Directory Domain Services Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-401
CPEs cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 23h2 Windows 11 23h2 Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1 Windows Server 2022 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:36:25.818Z

Reserved: 2026-08-03T22:50:31.850Z

Link: CVE-2026-69809

cve-icon Vulnrichment

Updated: 2026-09-08T20:46:53.379Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:19:52.687

Modified: 2026-09-24T19:12:06.440

Link: CVE-2026-69809

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:56:10Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime