ZeroHour

CVE-2026-69809

mass

Unauthenticated Memory-Leak DoS in Microsoft Active Directory Domain Services

CVSS 3.1
7.5 high
EPSS
1%p64
Published
()
Modified
AI analysis

CVE-2026-69809 is a use-after-free-style memory leak (CWE-401) in Microsoft's Active Directory Domain Services, where allocated memory is not released after its effective lifetime. An unauthenticated remote attacker can trigger the flaw by sending network traffic to a domain controller, causing memory to accumulate until the service is exhausted. The impact is denial of service only — no confidentiality or integrity compromise — but the availability impact is rated high, meaning a domain controller can become unresponsive or need restarting. Any organization running the AD DS role on affected Windows Server releases is potentially affected, since the attack requires only network reachability to the DC, not credentials or user interaction. As of now there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a modest 1.1% probability of exploitation within 30 days; it was fixed in Microsoft's September 2026 Patch Tuesday release.

What to do: Apply the September 2026 cumulative Windows Server security updates to all domain controllers, prioritizing DCs reachable from untrusted networks (VPN, DMZ, or internet-exposed LDAP/Kerberos endpoints). Until patched, restrict network access to domain controllers to trusted sources where possible, since the DoS requires only unauthenticated network reachability. Check your environment for exposed DC services and monitor Microsoft's advisory for the definitive affected-version list.

Affected
Microsoft Active Directory Domain Services (AD DS role on Windows Server)
Estimated exposure
massmillions of domain controllers worldwide (AD DS underpins nearly every Windows enterprise network, with hundreds of thousands of LDAP/DC endpoints publicly… — AD DS is the default directory service for virtually all Windows Server enterprise deployments, and public internet-wide scans routinely enumerate hundreds of thousands of exposed domain-controller endpoints, so the aggregate install base…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing release of memory after effective lifetime in Active Directory Domain Services allows an unauthorized attacker to deny service over a network.

Weakness
CWE-401
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Microsoft's September 2026 Patch Tuesday fixes a record 966 flaws, including two Windows zero-days actively exploited to gain SYSTEM privileges.

Microsoft's September 2026 Patch Tuesday addresses a record 966 vulnerabilities, including 105 rated Critical, 81 of them remote code execution bugs. Two zero-days were actively exploited: a Windows Update Stack link-following flaw and a Windows ALPC heap-based buffer overflow, both allowing local elevation to SYSTEM privileges. The ALPC flaw was reported by Volexity and Proofpoint researchers, while the Update Stack flaw was credited to Romain Deperne and the Microsoft Threat Intelligence Centre. Microsoft shared no details on how the flaws were exploited in attacks.

BleepingComputer · 7d agoAdvisory in the wildCVE-2026-69805CVE-2026-58649CVE-2026-69806+27 CVEs1