Stack-based Buffer Overflow Vulnerability in Active Directory Federation Services by Microsoft
CVE-2026-50304

7.5HIGH

What is CVE-2026-50304?

A stack-based buffer overflow vulnerability exists in Active Directory Federation Services, which can be exploited by an unauthorized attacker to perform denial of service attacks over a network. This vulnerability could potentially disrupt service availability, impacting users and applications depending on AD FS for authentication mechanisms.

Affected Version(s)

Microsoft .NET Framework 3.5 AND 4.7.2 Windows 10 Version 1607 for 32-bit Systems 4.7.0 < 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0

Microsoft .NET Framework 3.5 AND 4.8 Windows 10 Version 1809 for 32-bit Systems 4.8.0 < 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0

Microsoft .NET Framework 3.5 AND 4.8.1 Windows 10 Version 21H2 for 32-bit Systems 4.8.1 < 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.