Azure Active Directory Denial of Service Vulnerability

Plan PatchCVSS 7.5CVE-2026-50653Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

A denial of service vulnerability exists in Microsoft .NET Framework versions 3.5, 4.7.2, 4.8, and 4.8.1 across multiple Windows operating systems. An infinite loop with no reachable exit condition in Azure Active Directory-related code allows an unauthorized attacker to deny service over a network by sending specially crafted requests. The affected versions span Windows 10 (versions 1607, 1809, 21H2, 22H2, 26H1), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 on both 32-bit and 64-bit architectures, as well as Server Core installations.

What this means
What could happen
An attacker on the network can trigger an infinite loop in .NET Framework that causes a denial of service, potentially disrupting applications running on Windows systems that rely on these frameworks.
Who's at risk
Organizations running Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, Windows Server 2022, or Windows Server 2025 systems with Microsoft .NET Framework 3.5, 4.7.2, 4.8, or 4.8.1 installed should assess this vulnerability. This affects IT infrastructure, application servers, and engineering workstations that host .NET-based applications or services.
How it could be exploited
An attacker sends specially crafted network traffic to an application running on the affected .NET Framework, triggering an unreachable exit condition in a loop that consumes resources and stops the application from responding to legitimate requests.
Prerequisites
  • Network access to the application running on affected .NET Framework
  • No authentication required
  • Application must be exposed to untrusted network or attacker must be on the local network
Remotely exploitableNo authentication requiredLow complexity attackNo patch available yet (exploitation assessment: exploitation less likely)
Exploitability
Some exploitation risk — EPSS score 1.2%
Affected products (42)
42 with fix
ProductAffected VersionsFix Status
Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit SystemsAll versionsBuild 4.8.4803.0
Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based SystemsAll versionsBuild 4.8.4803.0
Microsoft .NET Framework 4.8 on Windows Server 2016All versionsBuild 4.8.4803.0
Microsoft .NET Framework 4.8 on Windows Server 2016 (Server Core installation)All versionsBuild 4.8.4803.0
Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0
Remediation & Mitigation
0/5
Do now
0/1
WORKAROUNDRestrict network access to applications running on .NET Framework to trusted networks only using firewall rules
Schedule — requires maintenance window
0/3

Patching may require device reboot — plan for process interruption

HOTFIXInstall the 2026-Jul security update for Microsoft .NET Framework 4.8 (Build 4.8.4803.0 or later)
HOTFIXInstall the 2026-Jul security update for Microsoft .NET Framework 4.7.2 (Build 4.7.4143.0 or later)
HOTFIXInstall the 2026-Jul security update for Microsoft .NET Framework 4.8.1 (Build 4.8.9339.0 or later for Windows Server 2022/Windows 10, Build 4.8.9340.0 for Windows Server 2025/Windows 11)
Long-term hardening
0/1
HARDENINGImplement network segmentation to isolate Windows systems running vulnerable .NET Framework versions from untrusted networks
API: /api/v1/advisories/9222af75-dc83-4f64-b932-32a88019b454

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.