Active Directory Federation Services Elevation of Privilege Vulnerability

Act NowCVSS 7.8CVE-2026-56155Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally on Windows 10 and Windows Server systems. An attacker with standard user credentials can exploit weak permission controls to gain higher privileges on the system.

What this means
What could happen
An attacker with standard user credentials on your Windows or Windows Server system can escalate to higher privileges on the local machine, potentially gaining administrative control of the system.
Who's at risk
Windows and Windows Server administrators running Active Directory Federation Services (AD FS), which is used for single sign-on and authentication in enterprise networks. This affects domain controllers, authentication servers, and any systems with AD FS roles installed, impacting utilities with Microsoft-based identity infrastructure.
How it could be exploited
An attacker with a valid user account on a Windows or Windows Server machine with Active Directory Federation Services can exploit weak permission controls in AD FS to run commands with elevated privileges, bypassing normal access restrictions.
Prerequisites
  • Valid user account on the affected Windows or Windows Server system
  • Local network access to the system
  • Active Directory Federation Services (AD FS) installed and configured
actively exploited (KEV)remotely exploitablelow complexityno authentication required for local escalation
Exploitability
Actively exploited — confirmed by CISA KEV
Affected products (11)
11 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Windows Server 2025All versionsBuild 10.0.26100.33158
Windows 10 Version 1607 for 32-bit SystemsAll versionsBuild 10.0.14393.9339
Remediation & Mitigation
0/4
Do now
0/3
Windows Server 2019
HOTFIXPrioritize patching Windows Server 2019, Windows Server 2022, and Windows Server 2025 systems, as these are most likely hosting AD FS in your environment
All products
HOTFIXApply the July 2026 Microsoft security update to your affected Windows 10 and Windows Server systems immediately
HARDENINGRestrict local administrative access and limit user privileges to only what is required for their role
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

WORKAROUNDAudit and disable AD FS on systems where it is not actively required
API: /api/v1/advisories/468f5b0e-e063-44f4-b718-2bfd89f9d013

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Active Directory Federation Services Elevation of Privilege Vulnerability | CVSS 7.8 - OTPulse