Impact
The vulnerability appears as an unbounded resource allocation in Active Directory Federation Services (AD FS). In the current configuration, an unauthorized attacker can submit requests that cause AD FS to consume arbitrary amounts of memory and CPU resources, ultimately exhausting the target system and preventing legitimate users from accessing AD FS services. This results in a denial of service that affects authentication and single‑sign‑on functionality across the network.
Affected Systems
Affected clients include Microsoft Windows 10 version 1607 and 1809, as well as Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, in both standard and Server Core installations. These versions run the AD FS component that is vulnerable to the unbounded allocation issue.
Risk and Exploitability
The CVSS score is 5.9, indicating a moderate potential impact. The EPSS score is not available, so the probability of exploitation is unknown, but because the attack vector is network‑bound and no countermeasures currently exist, the risk remains noteworthy. The vulnerability is not listed in the CISA KEV catalog, and no public exploitation cases have been reported, yet the lack of throttling could enable attackers to launch an effective denial‑of‑service attack with sufficient network access.
OpenCVE Enrichment