Impact
The vulnerability involves insufficient granularity of access control in Active Directory Federation Services, which an authorized attacker can abuse to gain higher system privileges on the affected host, potentially enabling further compromise of the local environment. The weakness is identified as CWE-1220, typically associated with improper handling of system configuration and privilege boundaries.
Affected Systems
Affected platforms include Microsoft Windows 10 versions 1607 and 1809, and Microsoft Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, both standard and Server Core installations, all versions of AD FS running on those operating systems.
Risk and Exploitability
The CVSS score is 7.8, indicating a high severity of local privilege escalation. The EPSS score is 2%, indicating a moderately low probability of exploitation in the wild, yet the vulnerability is listed in the CISA KEV catalog, indicating it has been confirmed as exploited. Attackers would need existing local or domain-level access and the ability to use AD FS services; the attack surface is limited to systems running AD FS with the affected versions. While exploitation risk is moderate, the potential impact on confidentiality, integrity, and availability makes timely remediation essential.
OpenCVE Enrichment