Azure Active Directory Denial of Service Vulnerability
A denial of service vulnerability exists in Microsoft .NET Framework versions 3.5, 4.7.2, 4.8, and 4.8.1 across multiple Windows operating systems. An infinite loop with no reachable exit condition in Azure Active Directory-related code allows an unauthorized attacker to deny service over a network by sending specially crafted requests. The affected versions span Windows 10 (versions 1607, 1809, 21H2, 22H2, 26H1), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 on both 32-bit and 64-bit architectures, as well as Server Core installations.
- Network access to the application running on affected .NET Framework
- No authentication required
- Application must be exposed to untrusted network or attacker must be on the local network
Patching may require device reboot — plan for process interruption
/api/v1/advisories/9222af75-dc83-4f64-b932-32a88019b454Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.