Impact
A stack-based buffer overflow has been identified in Active Directory Federation Services (AD FS). By sending a specially crafted federation request over the network, an unauthenticated attacker can trigger the overflow, causing the AD FS service to crash and become unavailable. No other confidentiality, integrity, or privilege escalation effects have been reported; Windows 10 systems from 1607 through 22H2, Windows 11 systems from 24H2 through 26H1, and Windows Server releases from 2012 to 2025—including Server Core installations—are all affected. All related .NET Framework releases from 3.5 to 4.8.1, including the 4.6.2, 4.7, 4.7.1, and 4.7.2 branches, also contain the vulnerable AD FS component.
Affected Systems
Affected products include Microsoft Windows 10 versions 1607 through 22H2, Microsoft Windows 11 versions 24H2 through 26H1, and Microsoft Windows Server releases 2012 through 2025, including Server Core installations. All versions of the .NET Framework from 3.5 to 4.8.1 also contain the vulnerable AD FS component.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1 % signifies a low to moderate likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, over the network, and requires no authentication to send the malicious request. The potential damage can disrupt authentication for users and services that depend on AD FS, but the limited exploitation probability moderates immediate urgency relative to higher‑risk flaws.
OpenCVE Enrichment