CVE-2026-50304
Analyzed Analyzed - Analysis Complete

Stack-based Buffer Overflow in Active Directory Federation Services

Vulnerability report for CVE-2026-50304, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-22

Assigner: Microsoft Corporation

Description

Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-22
Generated
2026-08-04
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 10 associated CPEs
Vendor Product Version / Range
microsoft windows_server_2012 r2
microsoft windows_server_2012 *
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_server_2016 to 10.0.14393.9339 (exc)
microsoft windows_server_2019 to 10.0.17763.9020 (exc)
microsoft windows_server_2022 to 10.0.20348.5386 (exc)
microsoft windows_server_2025 to 10.0.26100.33158 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-50304 is a stack-based buffer overflow vulnerability in Microsoft Active Directory Federation Services (AD FS). This flaw allows an unauthorized attacker to send specially crafted input over a network, causing a buffer overflow in the service.

A buffer overflow occurs when a program writes more data to a buffer than it can hold, leading to memory corruption. In this case, the overflow can cause the AD FS service to crash or become unresponsive, resulting in a denial of service (DoS).

The vulnerability does not require authentication (PR:N) and can be exploited remotely (AV:N), making it accessible to attackers over the internet or a local network.

Impact Analysis

This vulnerability can impact you in the following ways:

  • Denial of Service (DoS): An attacker can exploit this flaw to crash or disrupt the Active Directory Federation Services, preventing legitimate users from accessing federated authentication services.
  • Service Outages: If AD FS is critical for your organization's authentication workflows (e.g., single sign-on or cloud-based applications), its unavailability can halt business operations.
  • Potential for Further Exploitation: While this CVE is classified as a DoS, buffer overflow vulnerabilities can sometimes be leveraged for remote code execution (RCE) in other scenarios, though this is not confirmed for CVE-2026-50304.
Compliance Impact

This vulnerability may affect compliance with common standards and regulations in the following ways:

  • GDPR (General Data Protection Regulation): If AD FS is used to authenticate access to personal data, a DoS attack could disrupt data availability, potentially violating GDPR's requirement for ensuring the availability and resilience of processing systems (Article 32).
  • HIPAA (Health Insurance Portability and Accountability Act): For organizations handling protected health information (PHI), AD FS downtime could prevent access to critical systems, leading to non-compliance with HIPAA's availability and security requirements (e.g., Security Rule Β§164.308(a)(7)).
  • Other Standards: Frameworks like ISO 27001 or NIST SP 800-53 emphasize the need for system availability and resilience. A DoS vulnerability could indicate a failure to implement adequate controls (e.g., ISO 27001 A.12.2.1 or NIST AC-17).

However, the specific impact on compliance depends on how AD FS is used in your environment and whether the vulnerability leads to actual disruptions or data breaches.

Mitigation Strategies

Apply the security update provided by Microsoft for CVE-2026-50304. This update addresses the stack-based buffer overflow in Active Directory Federation Services and mitigates the denial of service risk.

  • Visit the Microsoft Security Response Center (MSRC) update guide for CVE-2026-50304 to download and install the patch.
  • Ensure all systems running Active Directory Federation Services are updated to the latest secure version.
  • Monitor Microsoft's official communications for any additional guidance or updates related to this vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50304. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart