Impact
An infinite loop exists in the Active Directory Federation Services (AD FS) component, causing a process to consume CPU and memory until it becomes unresponsive. The flaw is a classic CWE‑835 weak input or control‑flow issue. If triggered, the AD FS service fails to accept authentication requests, effectively denying authentication services to all clients that rely on AD FS.
Affected Systems
The vulnerability impacts Microsoft .NET Framework 3.5 and its bundled versions with 4.7.2, 4.8, and 4.8.1, as well as .NET Framework 4.6.2 through 4.7.2 and 4.8. In addition, all Windows 10 releases starting with version 1607 through 22H2, Windows 11 releases 24H2, 25H2, and 26H1, and every Windows Server build from 2012 to 2025 (including Server Core editions) are affected across x86, x64, and ARM architectures.
Risk and Exploitability
The CVSS base score of 7.5 indicates high severity, and the EPSS score of about 1 % shows that exploitation is possible but not widespread. The flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could trigger the infinite loop by sending an unauthenticated network request to the AD FS service, leading to resource exhaustion, potential service disruption, and denial of authentication services. Because the issue can be exploited remotely without credentials, rapid patching and protective measures such as limiting network access are prudent.
OpenCVE Enrichment