Impact
The vulnerability is a stack-based buffer overflow in Windows Active Directory Federation Services (AD FS). An attacker can send a malformed federation request that corrupts a stack buffer, allowing the service to terminate or restart, resulting in a denial of service that disables AD FS functionality. This flaw is categorized as CWE‑121.
Affected Systems
Affected Windows operating systems include Windows 10 versions 1607, 1809, 21H2, and 22H2, Windows 11 versions 24H2, 25H2, and 26H1, and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025, both normal and Server Core installations, across x86, x64 and arm64 architectures.
Risk and Exploitability
The CVSS score of 7.5 indicates moderate‑to‑high severity with medium complexity and a sole impact on AD FS availability. EPSS is less than 1 %, suggesting a low current exploitation probability, and the issue is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote, requiring an attacker able to send specially crafted federation requests over the network to trigger the overflow.
OpenCVE Enrichment