Description
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
Published: 2026-07-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack‑based buffer overflow has been identified in the Active Directory Federation Services (AD FS) component of Windows. Based on the description, it is inferred that AD FS functions as the gateway for authenticating users and services; thus, a crash results in a loss of authentication availability for any client relying on the federation service. The weakness is categorized as CWE‑121 (Stack‑Based Buffer Overflow).

Affected Systems

Affected versions include Microsoft Windows 10 build 1607, 1809, 21H2, and 22H2, Windows 11 builds 24H2, 25H2, and 26H1, as well as Windows Server 2012 through 2025, covering both full and Server Core installations. All of these releases run the AD FS feature that contains the vulnerable code.

Risk and Exploitability

The CVSS score of 7.5 classifies the issue as high severity, yet the EPSS score of less than 1% indicates a low probability that exploitation will occur in the wild. The vulnerability is not mentioned in the CISA KEV catalog. Attackers who can reach the AD FS endpoint over the network and are not already authenticated can trigger the overflow by sending a crafted request, leading to a denial‑of‑service condition. Based on the description, it is inferred that the failure impacts authentication services, so organizations should assess the criticality of AD FS in their environment when weighing the risk.

Generated by OpenCVE AI on July 31, 2026 at 09:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update for AD FS as published on the MSRC advisory
  • Restrict inbound traffic to the AD FS service by implementing IP whitelisting, firewall rules, or network segmentation to limit exposure to trusted clients
  • Consider disabling legacy AD FS services or migrating to an alternative authentication solution, such as Azure AD, if the organization no longer requires the on‑premises federation component
  • Monitor AD FS logs for abnormal requests and configure alerts for repeated failures or crashes to detect potential exploitation attempts

Generated by OpenCVE AI on July 31, 2026 at 09:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
Title Windows Active Directory Federation Services Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-121
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows 10 21h2 Windows 10 22h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2012 Windows Server 2012 R2 Windows Server 2016 Windows Server 2019 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:53:05.095Z

Reserved: 2026-06-16T14:10:05.868Z

Link: CVE-2026-54983

cve-icon Vulnrichment

Updated: 2026-07-14T20:40:12.588Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:45:04Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow