Denial of Service Vulnerability in Active Directory Certificate Services by Microsoft
CVE-2025-29968
6.5MEDIUM
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 13 May 2025
What is CVE-2025-29968?
An improper input validation vulnerability in Active Directory Certificate Services (AD CS) enables an authorized attacker to exploit the flaw, potentially leading to denial of service conditions over the network. This can disrupt normal operations, impacting availability and user access. Organizations utilizing AD CS should take immediate precautions to mitigate the risks associated with this vulnerability.
Affected Version(s)
Windows Server 2008 Service Pack 2 x64-based Systems 6.0.6003.0 < 6.0.6003.23279
Windows Server 2008 R2 Service Pack 1 (Server Core installation) x64-based Systems 6.1.7601.0 < 6.1.7601.27729
Windows Server 2008 R2 Service Pack 1 x64-based Systems 6.1.7601.0 < 6.1.7601.27729