Impact
A stack‑based buffer overflow has been identified in the Active Directory Federation Services (AD FS) component of Windows. Based on the description, it is inferred that AD FS functions as the gateway for authenticating users and services; thus, a crash results in a loss of authentication availability for any client relying on the federation service. The weakness is categorized as CWE‑121 (Stack‑Based Buffer Overflow).
Affected Systems
Affected versions include Microsoft Windows 10 build 1607, 1809, 21H2, and 22H2, Windows 11 builds 24H2, 25H2, and 26H1, as well as Windows Server 2012 through 2025, covering both full and Server Core installations. All of these releases run the AD FS feature that contains the vulnerable code.
Risk and Exploitability
The CVSS score of 7.5 classifies the issue as high severity, yet the EPSS score of less than 1% indicates a low probability that exploitation will occur in the wild. The vulnerability is not mentioned in the CISA KEV catalog. Attackers who can reach the AD FS endpoint over the network and are not already authenticated can trigger the overflow by sending a crafted request, leading to a denial‑of‑service condition. Based on the description, it is inferred that the failure impacts authentication services, so organizations should assess the criticality of AD FS in their environment when weighing the risk.
OpenCVE Enrichment