ZeroHour

CVE-2026-69712

mass

Use-After-Free RCE in Microsoft Windows Key Distribution Center (KDC)

CVSS 3.1
8.8 high
EPSS
<1%p57
Published
()
Modified
AI analysis

CVE-2026-69712 is a use-after-free memory corruption flaw (CWE-416) in the Windows Key Distribution Center, the Kerberos key-issuing service that runs on Active Directory domain controllers. An authorized attacker holding valid low-privilege domain credentials can send crafted network requests that cause the KDC to reference freed memory, which Microsoft rates as leading to arbitrary code execution (CVSS 8.8, AV:N/AC:L/PR:L/UI:N). Successful exploitation would give the attacker code execution on the domain controller, typically as a highly privileged service, which in a domain environment commonly means control over the entire Active Directory forest. The flaw affects Windows deployments running the KDC — most critically domain controllers — though Microsoft's specific affected version ranges are not listed in the available data. As of now there is no known public proof-of-concept, the vulnerability is not in CISA's KEV catalog, and EPSS estimates only a 0.9% chance of exploitation within 30 days.

What to do: Track Microsoft's advisory and apply the security update to all domain controllers and other systems running the KDC as soon as a patched build is published. Because exploitation requires valid low-privilege credentials plus network reachability, restrict which networks and accounts can reach domain controllers (no direct internet exposure), and monitor domain controllers for anomalous KDC service restarts or crashes. Until patched, audit for any suspicious authentication activity from low-privilege accounts, since any valid domain credential is sufficient to attempt this attack.

Affected
Microsoft Windows Key Distribution Center (KDC), part of Windows — primarily Active Directory domain controllers (Windows Server);
Estimated exposure
massmillions of domain controllers worldwide (AD is near-universal in enterprise environments) — The KDC runs on every Active Directory domain controller, and AD is the dominant enterprise directory service, implying millions of deployed domain controllers globally, with public internet scans consistently showing on the order of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Key Distribution Center allows an authorized attacker to execute code over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.