8
CVE-2026-33826
- EPSS 0.93%
- Veröffentlicht 14.04.2026 16:57:50
- Zuletzt bearbeitet 17.04.2026 19:19:51
- Quelle secure@microsoft.com
- CVE-Watchlists
- Unerledigt
Windows Active Directory Remote Code Execution Vulnerability
Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows Server 2012 Versionr2
Microsoft ≫ Windows Server 2016 Version < 10.0.14393.9060
Microsoft ≫ Windows Server 2019 Version < 10.0.17763.8644
Microsoft ≫ Windows Server 2022 Version < 10.0.20348.5020
Microsoft ≫ Windows Server 2022 23h2 Version < 10.0.25398.2274
Microsoft ≫ Windows Server 2025 Version < 10.0.26100.32690
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.93% | 0.763 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| secure@microsoft.com | 8 | 2.1 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.