Impact
A stack-based buffer overflow exists in Active Directory Federation Services that can be triggered by an unauthorized attacker sending a crafted request over the network. The flaw leads to a denial of service, disrupting authentication and federation services. This weakness corresponds to CWE-121, which involves stack-based buffer overflows.
Affected Systems
The vulnerability affects Microsoft .NET Framework versions 3.5, 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8, and 4.8.1, as well as Microsoft Windows 10 versions 1607 and 1809, and Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, with both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, while the EPSS score of 1% reflects a low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. It is inferred that an attacker can exploit the flaw remotely without authentication by targeting the AD FS endpoint over the network, potentially causing widespread service disruption if the affected systems are running unpatched copies.
OpenCVE Enrichment