CVE-2026-50424
Analyzed Analyzed - Analysis Complete

Untrusted Pointer Dereference in Windows Domain Controller

Vulnerability report for CVE-2026-50424, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-22

Assigner: Microsoft Corporation

Description

Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-22
Generated
2026-08-03
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
microsoft windows_11_26h1 to 10.0.28000.2269 (exc)
microsoft windows_server_2025 to 10.0.26100.33158 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-822 The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-50424 is a vulnerability in the Windows Domain Controller. It involves an untrusted pointer dereference, which means the system incorrectly handles a pointer that can be manipulated by an attacker. This flaw allows an unauthorized attacker to cause a denial of service (DoS) over a network.

A denial of service occurs when the affected system becomes unresponsive or crashes, disrupting normal operations. In this case, the vulnerability does not allow the attacker to access or modify data but can render the Domain Controller unavailable.

Impact Analysis

If you are using a Windows Domain Controller, this vulnerability could impact you in the following ways:

  • Service disruption: An attacker could exploit this flaw to crash or make the Domain Controller unresponsive, leading to downtime for services that rely on it.
  • Network instability: Since the attack can be performed over a network, it may affect the availability of other connected systems or services.
  • Operational impact: Organizations depending on the Domain Controller for authentication, authorization, or directory services may experience interruptions in user access or administrative functions.
Compliance Impact

This vulnerability may affect compliance with common standards and regulations in the following ways:

  • GDPR: While this vulnerability does not directly involve data exposure or unauthorized access, a denial of service attack could disrupt the availability of systems processing personal data. GDPR requires organizations to ensure the availability and resilience of processing systems, so prolonged downtime could lead to non-compliance.
  • HIPAA: For organizations handling protected health information (PHI), HIPAA requires ensuring the availability of systems. A denial of service attack on a Domain Controller could disrupt access to critical healthcare systems, potentially violating HIPAA's availability requirements.
  • Other standards: Many compliance frameworks, such as ISO 27001 or NIST, require organizations to protect against threats that could disrupt service availability. Failure to mitigate this vulnerability could result in non-compliance with such standards.
Mitigation Strategies

Apply the security update provided by Microsoft for CVE-2026-50424. This update addresses the untrusted pointer dereference issue in Windows Domain Controller that could lead to a denial of service.

  • Visit the Microsoft Security Response Center (MSRC) update guide for CVE-2026-50424 to download and install the patch.
  • Ensure all Windows Domain Controllers are updated to the latest secure version as recommended by Microsoft.
  • Monitor Microsoft's official communications for any additional mitigation steps or workarounds if the patch cannot be applied immediately.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50424. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart