Executive brief
A vulnerability in Microsoft's Active Directory Federation Services (AD FS) allows an unauthorized person to crash the service over the network. AD FS is a critical component used to manage single sign-on and identity access across different applications. If exploited, this could prevent users from logging into corporate systems, causing a significant disruption to business operations.
Technical details
A stack-based buffer overflow (CWE-121) exists in Microsoft Active Directory Federation Services (AD FS). The vulnerability can be triggered by a remote, unauthenticated attacker over the network without any user interaction. Successful exploitation results in a denial-of-service (DoS) condition, crashing the AD FS service and preventing identity federation and authentication processes. Microsoft has released security updates to address this issue across multiple versions of Windows and Windows Server.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 All versions
- Microsoft Active Directory Federation Services (AD FS) All versions on affected Windows platforms
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory: Microsoft released security update guide for CVE-2026-54983