Azure Active Directory Denial of Service Vulnerability

Plan PatchCVSS 7.5CVE-2026-50652Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

A vulnerability in the deserialization logic of Microsoft .NET Framework allows an unauthenticated attacker on the network to send malicious serialized data to cause a denial of service. The affected versions are .NET Framework 3.5, 4.7.2, 4.8, and 4.8.1 running on Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025. No special privileges or user interaction are required to trigger the vulnerability.

What this means
What could happen
An attacker on the network can send malicious data to cause .NET Framework services to stop responding, disrupting any business applications that rely on those services.
Who's at risk
Organizations running .NET Framework 3.5, 4.7.2, 4.8, or 4.8.1 on Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 are affected. This impacts any enterprise applications built on .NET Framework, including Windows-based industrial automation systems, SCADA clients, and utility management software.
How it could be exploited
An attacker sends specially crafted data over the network to a .NET Framework application or service that deserializes untrusted input. The malicious data causes the service to crash or hang, making it unavailable.
Prerequisites
  • Network access to a .NET Framework application or service
  • The application must deserialize untrusted data from the network
remotely exploitableno authentication requiredlow complexity
Exploitability
Some exploitation risk — EPSS score 1.7%
Affected products (42)
42 with fix
ProductAffected VersionsFix Status
Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit SystemsAll versionsBuild 4.8.4803.0
Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based SystemsAll versionsBuild 4.8.4803.0
Microsoft .NET Framework 4.8 on Windows Server 2016All versionsBuild 4.8.4803.0
Microsoft .NET Framework 4.8 on Windows Server 2016 (Server Core installation)All versionsBuild 4.8.4803.0
Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0
Remediation & Mitigation
0/5
Schedule — requires maintenance window
0/5

Patching may require device reboot — plan for process interruption

HOTFIXUpdate Microsoft .NET Framework 4.8 to Build 4.8.4803.0 or later
HOTFIXUpdate Microsoft .NET Framework 3.5 to Build 3.0.30729.9168 or later (depending on OS version)
HOTFIXUpdate Microsoft .NET Framework 4.7.2 to Build 4.7.4143.0 or later
HOTFIXUpdate Microsoft .NET Framework 4.8.1 to Build 4.8.9339.0 or Build 4.8.9340.0 depending on Windows version
HOTFIXApply the 2026-Jul security update to Windows systems running affected .NET Framework versions
API: /api/v1/advisories/7e39931c-5476-4028-a4fe-5a30f8bbe97e

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Azure Active Directory Denial of Service Vulnerability | CVSS 7.5 - OTPulse