ZeroHour

CVE-2026-69359

mass

Heap Overflow Local Privilege Escalation in Microsoft Active Directory Domain Services

CVSS 3.1
7.8 high
EPSS
<1%p23
Published
()
Modified
AI analysis

CVE-2026-69359 is a heap-based buffer overflow (CWE-122) in Microsoft's Active Directory Domain Services (AD DS), patched as part of Microsoft's September 2026 Patch Tuesday, which addressed 966 flaws including 2 zero-days. An attacker who already holds a low-privileged authorized account on a system running the AD DS role (typically a domain controller) can trigger the overflow locally; per the CVSS vector the attack requires no user interaction and no remote access. Successful exploitation yields local elevation of privilege with high impact on confidentiality, integrity, and availability — on a domain controller this means the attacker gains elevated rights on the host that effectively expose the directory service itself. Any organization operating AD DS on Windows Server domain controllers is potentially affected. There is currently no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns a low 0.3% probability of exploitation within 30 days; whether this CVE is one of the two actively exploited zero-days reported in the September 2026 release is not stated in the available data.

What to do: Apply Microsoft's September 2026 Patch Tuesday security updates for Windows Server/AD DS as soon as possible, prioritizing domain controllers. In the interim, restrict interactive logon, RDP, and remote management rights on domain controllers to trusted administrators, since exploitation requires an authorized local account. Given no known public exploit and low EPSS (0.3%), treat this as routine patch prioritization rather than an emergency, but include all domain controllers in the patch wave.

Affected
Microsoft Active Directory Domain Services (AD DS) role on Windows Server
Estimated exposure
masshundreds of thousands to millions of domain controllers worldwide (order-of-magnitude estimate; no authoritative install count provided) — AD DS is a core role of Windows Server and is deployed on domain controllers in nearly every Windows enterprise domain, and public server-OS deployment estimates put global domain controller counts in the hundreds of thousands to millions.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Microsoft's September 2026 Patch Tuesday fixes a record 966 flaws, including two Windows zero-days actively exploited to gain SYSTEM privileges.

Microsoft's September 2026 Patch Tuesday addresses a record 966 vulnerabilities, including 105 rated Critical, 81 of them remote code execution bugs. Two zero-days were actively exploited: a Windows Update Stack link-following flaw and a Windows ALPC heap-based buffer overflow, both allowing local elevation to SYSTEM privileges. The ALPC flaw was reported by Volexity and Proofpoint researchers, while the Update Stack flaw was credited to Romain Deperne and the Microsoft Threat Intelligence Centre. Microsoft shared no details on how the flaws were exploited in attacks.

BleepingComputer · 7d agoAdvisory in the wildCVE-2026-69805CVE-2026-58649CVE-2026-69806+27 CVEs1