Command injection in Microsoft Windows and Windows Server - CVE-2026-49179

 

Command injection in Microsoft Windows and Windows Server - CVE-2026-49179

Published: August 12, 2026


Vulnerability identifier: #VU141735
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-49179
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to command injection in the NSPI RPC interface in Windows Active Directory Domain Services when handling crafted inputs from a client connection to a malicious server. A remote attacker can provide crafted inputs to execute arbitrary code.


Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2026-49179

Install security update from vendor's website.

Microsoft Windows - addressed in versions 10 21H2 10.0.19044.7663, 10 22H2 10.0.19045.7663, 10 1607 10.0.14393.9418, 10 1809 10.0.17763.9115, 11 23H2 10.0.22631.7517, 11 24H2 10.0.26100.9106, 11 24H2 10.0.26100.9168, 11 25H2 10.0.26200.9168, 11 26H1 10.0.28000.2704
Windows Server - addressed in versions 2012 R2 6.3.9600.23337, 2012 6.2.9200.26279, 2016 10.0.14393.9418, 2019 10.0.17763.9115, 2022 10.0.20348.5440, 2022 10.0.20348.5499, 2025 10.0.26100.33222, 2025 10.0.26100.33296

External References

Related Security Bulletins