Executive brief
Microsoft Active Directory Federation Services (AD FS), a component used to manage single sign-on and identity access across different applications, contains a security flaw. This vulnerability allows an attacker who already has basic access to a system to gain higher-level administrative privileges. If exploited, this could allow an unauthorized user to take full control of the identity management server, potentially compromising user credentials and corporate data.
Technical details
A privilege escalation vulnerability exists in Microsoft Active Directory Federation Services (AD FS) due to insufficient granularity of access control (CWE-1220). An attacker with local access and low-level privileges can exploit this flaw to gain elevated system permissions. The attack vector is local, requiring the attacker to already have an authorized account on the target system. Successful exploitation could lead to a complete compromise of the AD FS server, impacting confidentiality, integrity, and availability. Microsoft has released updates to address this issue across various Windows and Windows Server versions.
Affected products
- Microsoft Active Directory Federation Services (AD FS) Windows 10, Windows Server 2012, 2012 R2, 2016, 2019
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory