Stack-Based Buffer Overflow in Active Directory Federation Services by Microsoft
CVE-2026-50355
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 14 July 2026
What is CVE-2026-50355?
A stack-based buffer overflow exists in Microsoft Active Directory Federation Services, which could allow an unauthorized attacker to cause a denial-of-service condition over a network. This vulnerability enables the potential for disruption in service, making affected systems vulnerable to attacks aimed at crashing service availability. It is crucial for organizations using this service to apply recommended patches and updates to mitigate risks associated with this vulnerability.
Affected Version(s)
Microsoft .NET Framework 3.5 AND 4.7.2 Windows 10 Version 1607 for 32-bit Systems 4.7.0 < 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0
Microsoft .NET Framework 3.5 AND 4.8 Windows 10 Version 1809 for 32-bit Systems 4.8.0 < 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0
Microsoft .NET Framework 3.5 AND 4.8.1 Windows 10 Version 21H2 for 32-bit Systems 4.8.1 < 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0