Executive brief
A vulnerability exists in Microsoft's Active Directory Federation Services (AD FS), a component used to provide single sign-on access to systems and applications. An unauthorized attacker can exploit this flaw over the network to crash the service, preventing legitimate users from logging into their accounts or accessing corporate resources. This results in a significant disruption to business operations and identity management services.
Technical details
A stack-based buffer overflow (CWE-121) exists in Active Directory Federation Services (AD FS). The vulnerability is triggered when the service improperly handles specially crafted network requests, leading to memory corruption on the stack. An unauthenticated attacker can exploit this over the network (AV:N) with low complexity (AC:L) to cause the service to crash, resulting in a complete loss of availability (A:H) for authentication services. The flaw affects multiple versions of Windows and Windows Server; users should apply the latest security updates from Microsoft to remediate the issue.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 All versions
- Microsoft Active Directory Federation Services (AD FS) Included in affected Windows versions
Timeline
- 2026-07-14: disclosed: Vulnerability published by Microsoft and NVD
- 2026-07-14: advisory: Microsoft Security Response Center (MSRC) released update guide details