CVE-2026-50411
Analyzed Analyzed - Analysis Complete

Stack-based Buffer Overflow in Active Directory Federation Services

Vulnerability report for CVE-2026-50411, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-24

Assigner: Microsoft Corporation

Description

Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-24
Generated
2026-08-04
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 29 associated CPEs
Vendor Product Version / Range
microsoft windows_server_2012 r2
microsoft windows_server_2012 *
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_server_2016 to 10.0.14393.9339 (exc)
microsoft windows_server_2019 to 10.0.17763.9020 (exc)
microsoft windows_server_2022 to 10.0.20348.5386 (exc)
microsoft windows_server_2025 to 10.0.26100.33158 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft .net_framework 4.8.1
microsoft .net_framework 4.8
microsoft .net_framework 4.6.2
microsoft .net_framework 4.7
microsoft .net_framework 4.7.1
microsoft .net_framework 4.7.2
microsoft .net_framework 3.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-50411 is a stack-based buffer overflow vulnerability in Active Directory Federation Services (AD FS). This flaw allows an unauthorized attacker to send specially crafted input over a network, causing a buffer overflow in the AD FS service.

A buffer overflow occurs when a program writes more data to a buffer than it can hold, leading to memory corruption. In this case, the vulnerability can be exploited to cause a denial of service (DoS) condition, disrupting the availability of the AD FS service.

Detection Guidance

The provided context does not include specific detection methods or commands for identifying the presence of CVE-2026-50411 on a network or system. Detection typically involves checking the version of Active Directory Federation Services (AD FS) and verifying if it has been patched or updated to address this vulnerability.

You may use standard system and network monitoring tools to look for unusual activity, such as unexpected service disruptions or crashes in AD FS, which could indicate exploitation attempts. However, no explicit commands or tools are mentioned in the provided resources.

Impact Analysis

This vulnerability can impact you in the following ways:

  • Denial of Service (DoS): An attacker can exploit this flaw to crash the AD FS service, preventing legitimate users from accessing federated authentication services. This can disrupt business operations that rely on AD FS for single sign-on (SSO) or identity federation.
  • Unauthorized Access: While the primary impact is denial of service, buffer overflow vulnerabilities can sometimes be leveraged for further exploitation, such as remote code execution, though this is not confirmed for this specific CVE.
  • Operational Downtime: Organizations using AD FS for authentication may experience downtime, leading to productivity losses and potential financial costs associated with service restoration.
Compliance Impact

This vulnerability may affect compliance with common standards and regulations in the following ways:

  • GDPR: Under the General Data Protection Regulation (GDPR), organizations must ensure the availability and resilience of systems processing personal data. A denial of service attack exploiting this vulnerability could disrupt access to personal data, potentially violating GDPR requirements for data availability and security.
  • HIPAA: For organizations subject to the Health Insurance Portability and Accountability Act (HIPAA), this vulnerability could impact the availability of protected health information (PHI). HIPAA requires covered entities to ensure the confidentiality, integrity, and availability of PHI. A DoS attack could violate the availability requirement.
  • Other Standards: Compliance frameworks like ISO 27001 or NIST SP 800-53 emphasize the importance of system availability and resilience. A successful exploitation of this vulnerability could result in non-compliance with these standards if proper mitigations are not in place.

Organizations should assess their exposure to this vulnerability and apply patches or mitigations to maintain compliance with applicable regulations.

Mitigation Strategies

To mitigate CVE-2026-50411, follow these steps:

  • Apply the latest security updates provided by Microsoft for Active Directory Federation Services (AD FS). Refer to the Microsoft Security Update Guide for the specific patch related to this CVE.
  • If immediate patching is not possible, consider implementing network-level protections such as firewalls or intrusion prevention systems to block potential exploitation attempts.
  • Monitor AD FS servers for unusual activity or service disruptions that may indicate an attack.
  • Review Microsoft’s official guidance for additional workarounds or mitigations, as they may provide interim solutions until the patch can be applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50411. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart