Impact
An externally‑controlled format string vulnerability resides in the Active Directory Certificate Services (AD CS) component. The flaw allows an attacker who has authorized access to AD CS to supply format specifiers that can cause the service to reveal sensitive internal data to the network. The weakness matches CWE-134, which can expose confidential configuration or credential information, compromising the confidentiality of the affected systems.
Affected Systems
Microsoft Windows platforms listed in the CNA vendor/product entries are impacted. Specifically, Windows 10 Version 1607 and 1809, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022, Windows Server 2025, and their Server Core installation variants are all affected. No version ranges are provided beyond the listed releases, so any system running one of these builds is susceptible unless updated.
Risk and Exploitability
The CVSS score of 6.5 places this incident in the moderate severity range. EPSS data are currently unavailable, making precise probability assessment uncertain, but the requirement for authorized access suggests the exposure is limited to users with sufficient privileges on the AD CS service. The vulnerability is not currently listed in the CISA KEV catalog, so no confirmed public exploits are known. Nevertheless, the combination of a format‑string flaw and the potential to leak sensitive configuration details warrants prompt remediation.
OpenCVE Enrichment