CVE-2026-69809: Windows Active Directory Domain Services Denial of Service Vulnerability
Missing release of memory after effective lifetime in Active Directory Domain Services allows an unauthorized attacker to deny service over a network.
Other sources
Windows Active Directory Domain Services Denial of Service Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.7582Patch KB5122880 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.9445Patch KB5124008 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2954Patch KB5124012 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.9445Patch KB5124008 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5622Patch KB5122882 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.33438Patch KB5122871
Event History
Frequently Asked Questions
Which platforms are listed as affected?
The affected software list includes Microsoft Windows 11, Microsoft Windows Server 2022, and Microsoft Windows Server 2025. The vulnerability concerns Active Directory Domain Services.
Does exploitation require credentials, user interaction, or complex conditions?
No. The vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
Is the expected impact limited to availability?
Yes. The provided vector assigns no confidentiality or integrity impact and a high availability impact, consistent with denial of service.