Executive brief
A security vulnerability has been identified in Microsoft Active Directory Federation Services (AD FS), a service used to provide single sign-on access to systems and applications. An unauthorized attacker could exploit this flaw over the network to crash the service, leading to a denial-of-service condition. This would prevent legitimate users from logging into corporate resources and applications, potentially disrupting business operations.
Technical details
A stack-based buffer overflow (CWE-121) exists in Microsoft Active Directory Federation Services (AD FS). The vulnerability is reachable over the network and does not require authentication or user interaction. An attacker can exploit this by sending specially crafted requests to the AD FS endpoint, leading to memory corruption and a subsequent service crash (Denial of Service). While the primary impact is availability, stack overflows can sometimes lead to remote code execution, though only DoS is confirmed in this advisory. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.
Affected products
- Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9339
- Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
- Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
- Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows Server 2012 6.2.9200.0 to 6.2.9200.26226
- Microsoft Active Directory Federation Services
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory