CVE-2026-50366
Analyzed Analyzed - Analysis Complete

Null pointer dereference in Active Directory Domain Services

Vulnerability report for CVE-2026-50366, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-22

Assigner: Microsoft Corporation

Description

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-22
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 22 associated CPEs
Vendor Product Version / Range
microsoft windows_server_2012 r2
microsoft windows_server_2012 *
microsoft windows_11_26h1 to 10.0.28000.2269 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_server_2016 to 10.0.14393.9339 (exc)
microsoft windows_server_2019 to 10.0.17763.9020 (exc)
microsoft windows_server_2022 to 10.0.20348.5386 (exc)
microsoft windows_server_2025 to 10.0.26100.33158 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-50366 is a null pointer dereference vulnerability in Microsoft Active Directory Domain Services. This flaw allows an authorized attacker to cause a denial of service (DoS) condition over a network.

A null pointer dereference occurs when a program attempts to access memory at a location that is null or uninitialized. In this case, the vulnerability exists in Active Directory Domain Services, which is a critical component for managing network resources and authentication in Windows environments.

The attacker must be authorized, meaning they need valid credentials or access to the network to exploit this vulnerability. The impact is limited to service disruption, as the CVSS score indicates no impact on confidentiality or integrity.

Detection Guidance

The provided context does not include specific detection methods or commands for identifying this vulnerability on a network or system. Detection typically involves monitoring for unusual service disruptions or crashes in Active Directory Domain Services, but no technical details or commands are available in the given resources.

You may refer to Microsoft's official guidance or security tools like Microsoft Defender for Identity, Event Viewer logs, or Active Directory diagnostic tools to check for signs of exploitation or service instability.

Impact Analysis

This vulnerability can impact you in the following ways:

  • Denial of Service (DoS): An authorized attacker could exploit this flaw to crash or disrupt Active Directory Domain Services, leading to downtime for network authentication and resource management.
  • Operational Disruption: If Active Directory services are unavailable, users may be unable to log in, access shared resources, or perform other network-dependent tasks, affecting productivity.
  • Potential for Follow-up Attacks: While the vulnerability itself does not allow data theft or modification, a prolonged DoS condition could be used as a distraction for other malicious activities.
Compliance Impact

The impact of this vulnerability on compliance with standards and regulations depends on the context of your organization:

  • GDPR: While this vulnerability does not directly involve data exposure or unauthorized access, prolonged service disruption could violate GDPR's requirements for data availability and resilience. Organizations must ensure systems are available and functional to protect personal data.
  • HIPAA: For healthcare organizations, a denial of service affecting Active Directory could disrupt access to electronic protected health information (ePHI). HIPAA requires safeguards to ensure the availability of ePHI, so a DoS condition could lead to non-compliance if not mitigated promptly.
  • Other Standards: Many compliance frameworks, such as ISO 27001 or NIST, require organizations to maintain the availability of critical systems. A DoS vulnerability like this could indicate a failure to implement adequate security controls, potentially leading to compliance issues.

To maintain compliance, organizations should apply patches or mitigations provided by Microsoft to address this vulnerability.

Mitigation Strategies

To mitigate CVE-2026-50366, apply the security update provided by Microsoft as soon as possible. The update addresses the null pointer dereference issue in Active Directory Domain Services.

  • Visit the Microsoft Update Guide for CVE-2026-50366 to download and install the patch: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50366.
  • Ensure all domain controllers running Active Directory Domain Services are updated to the latest secure version.
  • Monitor network traffic and Active Directory logs for signs of exploitation attempts or service disruptions.
  • Restrict network access to domain controllers to authorized users and systems only, as the vulnerability requires authorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50366. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart