CVE-2026-57976
Analyzed Analyzed - Analysis Complete

Null pointer dereference in Active Directory Domain Services

Vulnerability report for CVE-2026-57976, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-22

Assigner: Microsoft Corporation

Description

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-22
Generated
2026-08-04
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 22 associated CPEs
Vendor Product Version / Range
microsoft windows_server_2012 r2
microsoft windows_server_2012 *
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_server_2016 to 10.0.14393.9339 (exc)
microsoft windows_server_2019 to 10.0.17763.9020 (exc)
microsoft windows_server_2022 to 10.0.20348.5386 (exc)
microsoft windows_server_2025 to 10.0.26100.33158 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-57976 is a vulnerability in Microsoft Active Directory Domain Services. It involves a null pointer dereference, which occurs when the software attempts to access or manipulate memory that has not been properly initialized or allocated.

An authorized attacker with low privileges (PR:L) can exploit this flaw over a network (AV:N) to cause a denial of service (DoS). This means the attacker can disrupt the availability of the Active Directory Domain Services, making it unresponsive or causing it to crash.

The vulnerability does not affect confidentiality or integrity (C:N/I:N) but has a high impact on availability (A:H). The CVSS base score for this vulnerability is 6.5, indicating a medium severity level.

Detection Guidance

The provided context does not include specific detection methods or commands for identifying the presence of CVE-2026-57976 on a network or system.

To detect this vulnerability, you would typically need to check for the presence of the affected software version or configuration. Since this is a null pointer dereference in Active Directory Domain Services, monitoring for unexpected service crashes or denial-of-service events related to Active Directory may indicate exploitation attempts.

For precise detection, refer to Microsoft's official guidance or security updates, which may include specific tools or logs to review. Common approaches might involve:

  • Reviewing Windows Event Logs for Active Directory service crashes or errors.
  • Using vulnerability scanning tools that support CVE-2026-57976 detection (e.g., Microsoft Defender for Identity, Nessus, or Qualys).
  • Checking for the installation of the relevant security update from Microsoft that patches this vulnerability.

No specific commands are provided in the context for direct detection.

Impact Analysis

If you are using Microsoft Active Directory Domain Services, this vulnerability could impact you in the following ways:

  • Denial of Service (DoS): An authorized attacker could exploit this vulnerability to crash or disrupt the Active Directory service, leading to downtime for directory-dependent applications and services.
  • Operational Disruption: Since Active Directory is critical for authentication and authorization, its unavailability could prevent users from accessing network resources, applications, or services that rely on it.
  • Potential for Follow-up Attacks: While this vulnerability itself does not allow data theft or modification, a prolonged DoS could create opportunities for other attacks or mask malicious activities.
Compliance Impact

This vulnerability could impact compliance with common standards and regulations in the following ways:

  • GDPR: Under GDPR, organizations must ensure the availability and resilience of processing systems and services. A denial of service caused by this vulnerability could lead to non-compliance if it disrupts access to personal data or prevents timely responses to data subject requests.
  • HIPAA: HIPAA requires covered entities to ensure the confidentiality, integrity, and availability of electronic protected health information (ePHI). A DoS attack exploiting this vulnerability could violate the availability requirement, potentially leading to non-compliance.
  • Other Standards: Many compliance frameworks, such as ISO 27001 or NIST SP 800-53, require organizations to protect against disruptions to critical services. Failure to mitigate this vulnerability could result in non-compliance with these standards.

Organizations should assess their exposure to this vulnerability and apply patches or mitigations to maintain compliance with relevant regulations.

Mitigation Strategies

Microsoft has likely provided patches or updates to address this vulnerability. Apply the latest security updates for Active Directory Domain Services as soon as possible.

  • Check the Microsoft Security Update Guide for CVE-2026-57976 to download and install the relevant patches.
  • Ensure all domain controllers are updated to the latest secure version.
  • Monitor Microsoft's official communications for any additional mitigation steps or workarounds.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-57976. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart