Impact
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to trigger a denial of service by sending crafted network requests that corrupt the service’s stack and cause it to crash. The flaw exists in how AD FS processes certain message payloads, leading to uncontrolled memory writes. When triggered, the AD FS service terminates, disrupting authentication and federation for all users relying on the service. This vulnerability is classified as CWE‑121 and results in loss of availability for the affected authentication infrastructure.
Affected Systems
Microsoft Windows 10 versions 1607 and 1809, Microsoft Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025 – including Server Core installations – as well as Microsoft .NET Framework 3.5, 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8, and 4.8.1 – are impacted. The flaw resides in the AD FS component present in these operating system variants.
Risk and Exploitability
The CVSS score of 7.5 classifies this as a high‑severity flaw, while the EPSS score of less than 1 % indicates a very low probability of exploitation in the wild. Based on the description, the likely attack vector is a remote, unauthenticated attacker sending crafted requests to the vulnerable AD FS service; this inference comes from the nature of the stack‑overflow flaw. The vulnerability is not listed in the CISA KEV catalog, implying it is not a widely known or actively exploited issue. The exploitation likelihood is therefore inferred from the EPSS metric and not from any observed attacks. Organizations should treat this as a high‑priority, patchable risk for any environment where AD FS is critical.
OpenCVE Enrichment