Microsoft has warned IT administrators about a critical issue affecting Windows Server 2025 domain controllers. After a restart , these servers may not handle network traffic correctly, which can cause disruptions in Active Directory (AD) environments.
See also: Windows Remote Desktop vulnerability allows RCE execution

The issue occurs because domain controllers load the standard firewall profile instead of the required domain firewall profile after restart.
Incorrect application of the firewall profile leads to several problems:
- Domain controllers may become inaccessible on the domain network
- Applications and services running on affected servers or remote devices may fail or remain inaccessible.
- Ports and protocols that should be restricted by the domain firewall profile may remain open, creating potential security risks.
This issue only affects Windows Server 2025 systems that host the Active Directory Domain Services role. Client systems or earlier server versions are not affected.
See also: Fixes for Windows zero-day vulnerability affecting NTLM
Microsoft has provided a temporary workaround to address the issue. Administrators can manually restart the network adapter on affected servers using PowerShell with the following command:
Restart-NetAdapter *

However, this solution must be applied after each system reboot, as the problem reoccurs every time the server is restarted.
To simplify this process, Microsoft suggests creating a scheduled task that will automatically restart the network adapter every time the domain controller is restarted.
See also: CISA: Cisco and Windows vulnerabilities in the KEV list
Windows Server is an operating system developed by Microsoft, designed specifically for use on servers. Unlike versions of Windows intended for personal computers, Windows Server offers tools and features that serve the needs of networking, user management, data storage, virtualization and security in a corporate or organizational environment. It is widely used by businesses to host websites, provide email services, centrally manage users through Active Directory and create cloud or virtual machines.
Source: cybersecuritynews
