AI analysis
CVE-2026-62813 is a use-after-free memory-corruption flaw (CWE-416) in Microsoft's Active Directory Domain Services (AD DS), the directory service role that runs on Windows Server domain controllers. A low-privileged, authenticated ("authorized") attacker can trigger it remotely with crafted network traffic to the AD DS service under conditions where the service accesses memory that has already been freed; the high attack-complexity rating (AC:H) means successful exploitation depends on timing and memory state and is less reliably repeatable. A successful attack yields remote code execution on the domain controller with high impact to confidentiality, integrity, and availability, potentially giving an attacker control of the system and the directory that handles authentication for the environment. Any organization running Windows Server domain controllers with the AD DS role is potentially affected; Microsoft shipped the fix in its September 2026 Patch Tuesday release, which addressed 966 flaws including 2 zero-days. Exploitation has not been observed: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.6% probability of exploitation within 30 days (48th percentile).
What to do: Apply Microsoft's September 2026 Patch Tuesday security updates for AD DS to all Windows Server domain controllers as soon as practical, prioritizing any domain controllers reachable from the internet or partner networks. Because the flaw requires only low-privileged authenticated access, review which untrusted users, service accounts, or trusts can authenticate to domain controllers, and restrict LDAP/RPC network access to DCs from untrusted segments. No public exploit exists yet, but confirm the exact affected and fixed builds in Microsoft's advisory and monitor for escalation to active exploitation.
Affected
| Microsoft Active Directory Domain Services (Windows Server domain controllers with the AD DS role) | — |
Estimated exposure
mass≈1M+ domain controllers worldwide, with hundreds of thousands directly exposed in public internet scans — AD DS is the default directory service deployed by the overwhelming majority of Windows-ecosystem organizations, public internet-wide scans routinely show hundreds of thousands of exposed LDAP/domain-controller endpoints, and total…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.