KB5035855Catastrophic

Domain Controller memory leak crashes enterprises

What broke

March’s server update introduced a memory leak in LSASS — the process responsible for all authentication on Windows domain controllers. As the DC serviced Kerberos requests, LSASS memory consumption grew without limit until the server exhausted all RAM, hung, and crashed. In production environments running hundreds of domain controllers, this was a cascading disaster. Microsoft needed emergency out-of-band patches ten days later. It’s reassuring to know that the process underpinning every Windows domain login can be turned into a memory bomb by a routine security update.

Sources

  1. BleepingComputer: KB5035855 incident report
  2. BleepingComputer: KB5035855 incident report

Related Windows update incidents