ZeroHour

CVE-2026-62813

mass

Use-after-free RCE in Microsoft Active Directory Domain Services

CVSS 3.1
7.5 high
EPSS
<1%p48
Published
()
Modified
AI analysis

CVE-2026-62813 is a use-after-free memory-corruption flaw (CWE-416) in Microsoft's Active Directory Domain Services (AD DS), the directory service role that runs on Windows Server domain controllers. A low-privileged, authenticated ("authorized") attacker can trigger it remotely with crafted network traffic to the AD DS service under conditions where the service accesses memory that has already been freed; the high attack-complexity rating (AC:H) means successful exploitation depends on timing and memory state and is less reliably repeatable. A successful attack yields remote code execution on the domain controller with high impact to confidentiality, integrity, and availability, potentially giving an attacker control of the system and the directory that handles authentication for the environment. Any organization running Windows Server domain controllers with the AD DS role is potentially affected; Microsoft shipped the fix in its September 2026 Patch Tuesday release, which addressed 966 flaws including 2 zero-days. Exploitation has not been observed: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.6% probability of exploitation within 30 days (48th percentile).

What to do: Apply Microsoft's September 2026 Patch Tuesday security updates for AD DS to all Windows Server domain controllers as soon as practical, prioritizing any domain controllers reachable from the internet or partner networks. Because the flaw requires only low-privileged authenticated access, review which untrusted users, service accounts, or trusts can authenticate to domain controllers, and restrict LDAP/RPC network access to DCs from untrusted segments. No public exploit exists yet, but confirm the exact affected and fixed builds in Microsoft's advisory and monitor for escalation to active exploitation.

Affected
Microsoft Active Directory Domain Services (Windows Server domain controllers with the AD DS role)
Estimated exposure
mass≈1M+ domain controllers worldwide, with hundreds of thousands directly exposed in public internet scans — AD DS is the default directory service deployed by the overwhelming majority of Windows-ecosystem organizations, public internet-wide scans routinely show hundreds of thousands of exposed LDAP/domain-controller endpoints, and total…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Microsoft's September 2026 Patch Tuesday fixes a record 966 flaws, including two Windows zero-days actively exploited to gain SYSTEM privileges.

Microsoft's September 2026 Patch Tuesday addresses a record 966 vulnerabilities, including 105 rated Critical, 81 of them remote code execution bugs. Two zero-days were actively exploited: a Windows Update Stack link-following flaw and a Windows ALPC heap-based buffer overflow, both allowing local elevation to SYSTEM privileges. The ALPC flaw was reported by Volexity and Proofpoint researchers, while the Update Stack flaw was credited to Romain Deperne and the Microsoft Threat Intelligence Centre. Microsoft shared no details on how the flaws were exploited in attacks.

BleepingComputer · 7d agoAdvisory in the wildCVE-2026-69805CVE-2026-58649CVE-2026-69806+27 CVEs1