Denial of Service Vulnerability in Active Directory Certificate Services by Microsoft
CVE-2025-29968

6.5MEDIUM

What is CVE-2025-29968?

An improper input validation vulnerability in Active Directory Certificate Services (AD CS) enables an authorized attacker to exploit the flaw, potentially leading to denial of service conditions over the network. This can disrupt normal operations, impacting availability and user access. Organizations utilizing AD CS should take immediate precautions to mitigate the risks associated with this vulnerability.

Affected Version(s)

Windows Server 2008 Service Pack 2 x64-based Systems 6.0.6003.0 < 6.0.6003.23279

Windows Server 2008 R2 Service Pack 1 (Server Core installation) x64-based Systems 6.1.7601.0 < 6.1.7601.27729

Windows Server 2008 R2 Service Pack 1 x64-based Systems 6.1.7601.0 < 6.1.7601.27729

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-29968 : Denial of Service Vulnerability in Active Directory Certificate Services by Microsoft