Active Directory Federation Services Elevation of Privilege Vulnerability
Act NowCVSS 7.8CVE-2026-56155Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally on Windows 10 and Windows Server systems. An attacker with standard user credentials can exploit weak permission controls to gain higher privileges on the system.
What this means
What could happen
An attacker with standard user credentials on your Windows or Windows Server system can escalate to higher privileges on the local machine, potentially gaining administrative control of the system.
Who's at risk
Windows and Windows Server administrators running Active Directory Federation Services (AD FS), which is used for single sign-on and authentication in enterprise networks. This affects domain controllers, authentication servers, and any systems with AD FS roles installed, impacting utilities with Microsoft-based identity infrastructure.
How it could be exploited
An attacker with a valid user account on a Windows or Windows Server machine with Active Directory Federation Services can exploit weak permission controls in AD FS to run commands with elevated privileges, bypassing normal access restrictions.
Prerequisites
- Valid user account on the affected Windows or Windows Server system
- Local network access to the system
- Active Directory Federation Services (AD FS) installed and configured
actively exploited (KEV)remotely exploitablelow complexityno authentication required for local escalation
Exploitability
Actively exploited — confirmed by CISA KEV
Affected products (11)
11 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/4
Do now
0/3Windows Server 2019
HOTFIXPrioritize patching Windows Server 2019, Windows Server 2022, and Windows Server 2025 systems, as these are most likely hosting AD FS in your environment
All products
HOTFIXApply the July 2026 Microsoft security update to your affected Windows 10 and Windows Server systems immediately
HARDENINGRestrict local administrative access and limit user privileges to only what is required for their role
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
WORKAROUNDAudit and disable AD FS on systems where it is not actively required
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/468f5b0e-e063-44f4-b718-2bfd89f9d013Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.