CVE-2026-69712
massUse-After-Free RCE in Microsoft Windows Key Distribution Center (KDC)
CVE-2026-69712 is a use-after-free memory corruption flaw (CWE-416) in the Windows Key Distribution Center, the Kerberos key-issuing service that runs on Active Directory domain controllers. An authorized attacker holding valid low-privilege domain credentials can send crafted network requests that cause the KDC to reference freed memory, which Microsoft rates as leading to arbitrary code execution (CVSS 8.8, AV:N/AC:L/PR:L/UI:N). Successful exploitation would give the attacker code execution on the domain controller, typically as a highly privileged service, which in a domain environment commonly means control over the entire Active Directory forest. The flaw affects Windows deployments running the KDC — most critically domain controllers — though Microsoft's specific affected version ranges are not listed in the available data. As of now there is no known public proof-of-concept, the vulnerability is not in CISA's KEV catalog, and EPSS estimates only a 0.9% chance of exploitation within 30 days.
What to do: Track Microsoft's advisory and apply the security update to all domain controllers and other systems running the KDC as soon as a patched build is published. Because exploitation requires valid low-privilege credentials plus network reachability, restrict which networks and accounts can reach domain controllers (no direct internet exposure), and monitor domain controllers for anomalous KDC service restarts or crashes. Until patched, audit for any suspicious authentication activity from low-privilege accounts, since any valid domain credential is sufficient to attempt this attack.
| Microsoft Windows Key Distribution Center (KDC), part of Windows — primarily Active Directory domain controllers (Windows Server); | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Key Distribution Center allows an authorized attacker to execute code over a network.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.