ZeroHour

CVE-2026-69524

mass

Use-After-Free Remote Code Execution in Microsoft Active Directory Domain Services

CVSS 3.1
8.1 high
EPSS
<1%p51
Published
()
Modified
AI analysis

CVE-2026-69524 is a use-after-free memory corruption flaw (CWE-416) in Microsoft's Active Directory Domain Services (AD DS), patched as part of Microsoft's September 2026 Patch Tuesday release. An unauthorized attacker with no privileges or user interaction can trigger the flaw remotely over the network, though the high attack-complexity rating suggests reliable exploitation may depend on favorable memory or timing conditions. A successful exploit yields remote code execution on the target, with high impact to confidentiality, integrity, and availability — typically a domain controller holding an organization's central authentication data. Any organization running Windows Server with the AD DS role enabled (i.e., operating domain controllers) is affected. As of this data there are no known in-the-wild exploits, no public proof of concept, and a modest 0.7% EPSS probability of exploitation within 30 days.

What to do: Apply Microsoft's September 2026 security updates to all Windows Servers running the AD DS role, prioritizing domain controllers, and confirm the affected Windows Server builds against Microsoft's advisory. Until patched, restrict network access to domain controllers — avoid exposing LDAP/Kerberos endpoints to untrusted networks or the internet — and monitor for signs of anomalous activity against DCs.

Affected
Microsoft Windows Server with Active Directory Domain Services (AD DS) role
Estimated exposure
mass≈ millions of domain controllers worldwide (AD DS is the default directory service in Windows enterprise networks) — AD DS is deployed by virtually every Windows-based organization, typically with multiple domain controllers per environment, putting the global count of potentially affected systems well over 100,000, though DCs are usually internal rather…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Microsoft's September 2026 Patch Tuesday fixes a record 966 flaws, including two Windows zero-days actively exploited to gain SYSTEM privileges.

Microsoft's September 2026 Patch Tuesday addresses a record 966 vulnerabilities, including 105 rated Critical, 81 of them remote code execution bugs. Two zero-days were actively exploited: a Windows Update Stack link-following flaw and a Windows ALPC heap-based buffer overflow, both allowing local elevation to SYSTEM privileges. The ALPC flaw was reported by Volexity and Proofpoint researchers, while the Update Stack flaw was credited to Romain Deperne and the Microsoft Threat Intelligence Centre. Microsoft shared no details on how the flaws were exploited in attacks.

BleepingComputer · 7d agoAdvisory in the wildCVE-2026-69805CVE-2026-58649CVE-2026-69806+27 CVEs1