Active Directory Services
by Microsoft
CVEs (44)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-26923 | Hig | 0.79 | 8.8 | 0.83 | KEV | May 10, 2022 | Active Directory Domain Services Elevation of Privilege Vulnerability | |
| CVE-2021-42287 | Hig | 0.73 | 7.5 | 0.77 | KEV | Nov 10, 2021 | Active Directory Domain Services Elevation of Privilege Vulnerability | |
| CVE-2021-42278 | Hig | 0.72 | 7.5 | 0.73 | KEV | Nov 10, 2021 | Active Directory Domain Services Elevation of Privilege Vulnerability | |
| CVE-2025-21293 | Hig | 0.62 | 8.8 | 0.19 | Jan 14, 2025 | Active Directory Domain Services Elevation of Privilege Vulnerability | ||
| CVE-2011-3406 | Hig | 0.59 | 8.8 | 0.23 | Dec 14, 2011 | Buffer overflow in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold… | ||
| CVE-2026-45648 | Hig | 0.57 | 8.8 | 0.01 | Jun 9, 2026 | Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network. | ||
| CVE-2026-25177 | Hig | 0.57 | 8.8 | 0.01 | Mar 10, 2026 | Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2022-34691 | Hig | 0.57 | 8.8 | 0.02 | Aug 9, 2022 | Active Directory Domain Services Elevation of Privilege Vulnerability | ||
| CVE-2022-21857 | Hig | 0.57 | 8.8 | 0.03 | Jan 11, 2022 | Active Directory Domain Services Elevation of Privilege Vulnerability | ||
| CVE-2026-69546 | Hig | 0.53 | 8.1 | 0.01 | Sep 8, 2026 | Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69524 | Hig | 0.53 | 8.1 | 0.01 | Sep 8, 2026 | Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. | ||
| CVE-2021-42306 | Hig | 0.53 | 8.1 | 0.03 | Nov 24, 2021 | An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential on an Azure AD Application or Service Principal (which is not recommended). This vulnerability allows a… | ||
| CVE-2026-69359 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69809 | Hig | 0.49 | 7.5 | 0.01 | Sep 8, 2026 | Missing release of memory after effective lifetime in Active Directory Domain Services allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-62813 | Hig | 0.49 | 7.5 | 0.01 | Sep 8, 2026 | Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network. | ||
| CVE-2025-29810 | Hig | 0.49 | 7.5 | 0.03 | Apr 8, 2025 | Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-21351 | Hig | 0.49 | 7.5 | 0.03 | Feb 11, 2025 | Windows Active Directory Domain Services API Denial of Service Vulnerability | ||
| CVE-2021-42291 | Hig | 0.49 | 7.5 | 0.04 | Nov 10, 2021 | Active Directory Domain Services Elevation of Privilege Vulnerability | ||
| CVE-2021-42282 | Hig | 0.49 | 7.5 | 0.04 | Nov 10, 2021 | Active Directory Domain Services Elevation of Privilege Vulnerability | ||
| CVE-2022-38042 | Hig | 0.46 | 7.1 | 0.01 | Oct 11, 2022 | Active Directory Domain Services Elevation of Privilege Vulnerability |
- risk 0.79cvss 8.8epss 0.83
Active Directory Domain Services Elevation of Privilege Vulnerability
- risk 0.73cvss 7.5epss 0.77
Active Directory Domain Services Elevation of Privilege Vulnerability
- risk 0.72cvss 7.5epss 0.73
Active Directory Domain Services Elevation of Privilege Vulnerability
- risk 0.62cvss 8.8epss 0.19
Active Directory Domain Services Elevation of Privilege Vulnerability
- risk 0.59cvss 8.8epss 0.23
Buffer overflow in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold…
- risk 0.57cvss 8.8epss 0.01
Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.02
Active Directory Domain Services Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.03
Active Directory Domain Services Elevation of Privilege Vulnerability
- risk 0.53cvss 8.1epss 0.01
Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.03
An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential on an Azure AD Application or Service Principal (which is not recommended). This vulnerability allows a…
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to elevate privileges locally.
- risk 0.49cvss 7.5epss 0.01
Missing release of memory after effective lifetime in Active Directory Domain Services allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.01
Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.03
Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.
- risk 0.49cvss 7.5epss 0.03
Windows Active Directory Domain Services API Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.04
Active Directory Domain Services Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.04
Active Directory Domain Services Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.01
Active Directory Domain Services Elevation of Privilege Vulnerability
Page 1 of 3