Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-33826

Опубликовано: 14 апр. 2026
Источник: msrc
CVSS3: 8
EPSS Низкий

Описание

Windows Active Directory Remote Code Execution Vulnerability

Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.

FAQ

How could an attacker exploit this vulnerability?

To exploit this vulnerability, an authenticated attacker would need to send a specially crafted RPC call to an RPC host. This could result in remote code execution on the server side with the same permissions as the RPC service.

According to the CVSS metric, the attack vector is adjacent (AV:A). What does that mean for this vulnerability?

Successful exploitation of this vulnerability requires that an attacker needs to be in the same restricted Active Directory domain as the target system. The attack surface is not reachable from broader networks, which is why the attack vector is considered adjacent (AV:A).

Обновления

ПродуктСтатьяОбновление
Windows Server 2012 R2
Windows Server 2012 R2 (Server Core installation)
Windows Server 2016
Windows Server 2016 (Server Core installation)
Windows Server 2019
Windows Server 2019 (Server Core installation)
Windows Server 2022
Windows Server 2022 (Server Core installation)
Windows Server 2022, 23H2 Edition (Server Core installation)
Windows Server 2025

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation More Likely

EPSS

Процентиль: 42%
0.00535
Низкий

8 High

CVSS3

Связанные уязвимости

CVSS3: 8
nvd
4 месяца назад

Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.

CVSS3: 8
github
4 месяца назад

Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.

CVSS3: 8
fstec
4 месяца назад

Уязвимость службы каталогов Active Directory операционных систем Windows, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 42%
0.00535
Низкий

8 High

CVSS3