Impact
Stack-based buffer overflow in Active Directory Federation Services enables an unauthorized attacker to trigger a denial of service, preventing legitimate users from authenticating to the service. The weakness is a classic stack-based buffer overflow (CWE‑121) that can be exploited via a crafted network request, leading to process termination. The impact is limited to the availability of the AD FS service, but it can disrupt authentication for any application relying on AD FS, potentially affecting entire organizations.
Affected Systems
Microsoft Windows 10 versions 1607 and 1809, Windows Server releases 2012 through 2025 (including core installations), and Microsoft .NET Framework versions 3.5, 3.5/4.7.2, 3.5/4.8, 3.5/4.8.1, 4.6.2/4.7/4.7.1/4.7.2, and 4.8. All environments running AD FS on these platforms should verify that the update applies to their configuration.
Risk and Exploitability
With a CVSS score of 7.5 the vulnerability is moderately severe. The EPSS score of 1% indicates a low but nonzero likelihood of exploitation, and it is not currently listed in the CISA KEV catalog. The likely attack vector is remote network traffic directed to the AD FS service, so systems exposed to untrusted networks face higher risk. Exploitation requires sending a specific malicious payload; no authentication is required.
OpenCVE Enrichment