CVE-2026-50304: Windows Active Directory Federation Services Denial of Service Vulnerability
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
Other sources
Windows Active Directory Federation Services Denial of Service Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.9020Patch KB5099538 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.33158Patch KB5099536 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.9339Patch KB5099535 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5386Patch KB5099540 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.23291Patch KB5099444 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.26226Patch KB5099445 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.8983 & 3.0.30729.8978Patch KB5100985 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.8983 & 3.0.30729.8978Patch KB5100984 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0Patch KB5101003 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9182 & 3.0.30729.9168Patch KB5101014 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0Patch KB5101001 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0Patch KB5101004 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0Patch KB5101000 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0Patch KB5100998 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.7.4143.0Patch KB5100991 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.7.4143.0Patch KB5100990 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0Patch KB5101005 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0Patch KB5099535 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0Patch KB5100989 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0Patch KB5101006 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0Patch KB5101010 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0Patch KB5101008 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.4803.0Patch KB5101011 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.4803.0Patch KB5101009 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.4803.0Patch KB5101007 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.9340.0Patch KB5101002
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50304?
CVE-2026-50304 has a high severity rating of 7.5.
How does CVE-2026-50304 affect systems?
CVE-2026-50304 allows an unauthorized attacker to perform a denial of service attack on affected systems.
Which systems are impacted by CVE-2026-50304?
CVE-2026-50304 affects various versions of Microsoft Windows, including Windows Server 2012, 2016, 2019, 2022, and Windows 10.
What is the cause of the CVE-2026-50304 vulnerability?
The vulnerability in CVE-2026-50304 is caused by a stack-based buffer overflow in Active Directory Federation Services.
What steps should be taken to mitigate CVE-2026-50304?
To mitigate CVE-2026-50304, it is essential to update your systems with the latest security patches provided by Microsoft.