ZeroHour

CVE-2026-62810

mass

Heap Buffer Overflow in Microsoft AD CS Allows Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p15
Published
()
Modified
AI analysis

CVE-2026-62810 is a heap-based buffer overflow (CWE-122) in Active Directory Certificate Services (AD CS), the Windows Server role that operates an organization's certificate authority. An authorized attacker with low privileges on the affected server can trigger the overflow through local interaction with the AD CS service. Successful exploitation elevates the attacker's privileges on that host, with high impact on confidentiality, integrity, and availability. Any organization running the AD CS role on Windows Server is potentially affected; specific version ranges are not provided in the available data. Exploitation status: no public proof-of-concept, not listed in CISA KEV, and a low 0.2% EPSS probability, though the flaw was patched in Microsoft's September 2026 Patch Tuesday release.

What to do: Apply the September 2026 Microsoft security updates to all Windows Servers hosting the AD CS role, prioritizing issuing and enterprise CAs. Until patched, restrict interactive and remote logon rights on CA servers to trusted administrators and review local accounts with access to those hosts. Monitor vendor advisories for confirmed affected version ranges, since the flaw requires an authorized local account and no public exploit currently exists.

Affected
Microsoft Windows Server with the Active Directory Certificate Services (AD CS) role installed
Estimated exposure
masshundreds of thousands of AD CS server instances worldwide — AD CS is a core Windows Server role deployed in the majority of medium and large enterprise Active Directory environments, which together imply an install base on the order of hundreds of thousands of servers globally — an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Microsoft's September 2026 Patch Tuesday fixes a record 966 flaws, including two Windows zero-days actively exploited to gain SYSTEM privileges.

Microsoft's September 2026 Patch Tuesday addresses a record 966 vulnerabilities, including 105 rated Critical, 81 of them remote code execution bugs. Two zero-days were actively exploited: a Windows Update Stack link-following flaw and a Windows ALPC heap-based buffer overflow, both allowing local elevation to SYSTEM privileges. The ALPC flaw was reported by Volexity and Proofpoint researchers, while the Update Stack flaw was credited to Romain Deperne and the Microsoft Threat Intelligence Centre. Microsoft shared no details on how the flaws were exploited in attacks.

BleepingComputer · 7d agoAdvisory in the wildCVE-2026-69805CVE-2026-58649CVE-2026-69806+27 CVEs1