ZeroHour

CVE-2026-62762

mass

Null Pointer Dereference DoS in Microsoft Active Directory Domain Services

CVSS 3.1
6.5 medium
EPSS
<1%p53
Published
()
Modified
AI analysis

CVE-2026-62762 is a null pointer dereference (CWE-476) in Microsoft Active Directory Domain Services (AD DS), the directory service role that provides authentication and identity for Windows Server domains. An authorized, low-privileged user can trigger it remotely — with no user interaction and low attack complexity — by sending crafted network requests to a domain controller, causing the service to dereference a null pointer and crash. The impact is denial of service only (no confidentiality or integrity loss, per the CVSS 6.5 score with Availability:High), and because domain controllers are the authentication backbone of a domain, crashes can disrupt logons and dependent services across the environment. Any organization operating Windows Server domain controllers with the AD DS role is affected; the flaw was addressed in Microsoft's September 2026 Patch Tuesday, which fixed 966 flaws including 2 zero-days, though the data does not identify this CVE as one of the exploited zero-days. There is no known exploitation: no public proof-of-concept, not listed in CISA KEV, and only a modest 0.8% EPSS probability of exploitation within the next 30 days (percentile 53).

What to do: Apply Microsoft's September 2026 security updates for AD DS/Windows Server to every domain controller, including remote, branch, and lab DCs, as part of this month's Patch Tuesday rollout. Until patched, restrict which authenticated accounts and hosts can reach domain controllers over directory protocols such as LDAP, and avoid exposing DCs directly to the internet. After patching, review domain controller event logs for crashes or unexpected service restarts that could indicate probing or attempted exploitation.

Affected
Microsoft Active Directory Domain Services (AD DS) on Windows Server
Estimated exposure
masshundreds of millions of domain users via millions of deployed AD DS domain controllers (AD runs in ~90% of large enterprises) — Active Directory is the dominant enterprise identity platform — Microsoft has stated roughly 90% of Fortune 1000 organizations use it — and public internet scans show hundreds of thousands of LDAP-exposed domain controllers, implying…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

Weakness
CWE-476
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Microsoft's September 2026 Patch Tuesday fixes a record 966 flaws, including two Windows zero-days actively exploited to gain SYSTEM privileges.

Microsoft's September 2026 Patch Tuesday addresses a record 966 vulnerabilities, including 105 rated Critical, 81 of them remote code execution bugs. Two zero-days were actively exploited: a Windows Update Stack link-following flaw and a Windows ALPC heap-based buffer overflow, both allowing local elevation to SYSTEM privileges. The ALPC flaw was reported by Volexity and Proofpoint researchers, while the Update Stack flaw was credited to Romain Deperne and the Microsoft Threat Intelligence Centre. Microsoft shared no details on how the flaws were exploited in attacks.

BleepingComputer · 7d agoAdvisory in the wildCVE-2026-69805CVE-2026-58649CVE-2026-69806+27 CVEs1