Denial of Service Vulnerability in Active Directory Federation Services by Microsoft
CVE-2026-50324

5.9MEDIUM

What is CVE-2026-50324?

A vulnerability has been identified in Microsoft Active Directory Federation Services (AD FS), where a loop with an unreachable exit condition may be exploited by an unauthorized attacker. This flaw enables the attacker to initiate a denial of service (DoS) attack, potentially disrupting network services. Organizations using affected versions of AD FS should review the security advisories and apply the recommended patches to mitigate any risks.

Affected Version(s)

Microsoft .NET Framework 3.5 AND 4.7.2 Windows 10 Version 1607 for 32-bit Systems 4.7.0 < 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0

Microsoft .NET Framework 3.5 AND 4.8 Windows 10 Version 1809 for 32-bit Systems 4.8.0 < 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0

Microsoft .NET Framework 3.5 AND 4.8.1 Windows 10 Version 21H2 for 32-bit Systems 4.8.1 < 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.