Microsoft Warns of AD CS Vulnerability That Allows Attackers to Block Network Services

Microsoft Warns of AD CS Vulnerability That Allows Attackers to Block Network Services

Microsoft has issued an alert about a critical security vulnerability in Active Directory Certificate Services (AD CS), which could allow attackers to launch denial-of-service (DoS) attacks over a network.

Labeled as CVE-2025-29968, the vulnerability impacts various versions of Windows Server and has been rated as “Important” with a CVSS score of 6.5/5.7.

This flaw arises from inadequate input validation within AD CS, a vital component of Windows that handles the issuance and management of digital certificates for securing internal communications.

Flaw in AD CS Input Validation

Classified under CWE-20, Microsoft’s technical details specify that improper input validation in AD CS enables attackers with valid credentials to initiate network-based service disruptions.

Exploiting this vulnerability could render the AD CS service unresponsive, potentially halting authentication, secure communications, and other processes reliant on digital certificates across an organization.

Microsoft’s advisory highlights that this flaw can be exploited remotely with minimal attack effort and limited privileges. No user interaction is needed for exploitation, and while it doesn’t compromise data confidentiality or integrity, it poses a serious threat to system availability.

Security experts have expressed concern that this vulnerability could allow authenticated attackers with low-level access to disrupt certificate services, potentially crippling the security infrastructure of affected organizations.

Risk FactorsDetails
Affected Products– Windows Server 2022 (including 23H2 Edition) – Windows Server 2019 – Windows Server 2016 – Windows Server 2012/2012 R2 – Windows Server 2008/2008 R2
ImpactDenial of Service (DoS) through disruption of the AD CS service
Exploit Prerequisites– Low-privileged authenticated access – Active Directory Certificate Services (AD CS) role must be enabled
CVSS 3.1 Score6.5 (Important)

Impacted Systems

This vulnerability affects several versions of Windows Server, including:

  • Windows Server 2022 (including 23H2 Edition)
  • Windows Server 2019
  • Windows Server 2016
  • Windows Server 2012/2012 R2
  • Windows Server 2008/2008 R2

Both the standard and Server Core editions are vulnerable, as outlined in Microsoft’s advisory. The flaw specifically targets the AD CS role, which must be enabled on these servers for exploitation.

Security Patches Available

Microsoft has rolled out security patches to address this issue. IT administrators should apply the corresponding updates for their specific Windows Server version. For example:

  • Windows Server 2022: KB5058385 (Security Update 10.0.20348.3692)
  • Windows Server 2019: KB5058392 (Security Update 10.0.17763.7314)
  • Windows Server 2016: KB5058383 (Security Update 10.0.14393.8066)

Microsoft has classified the likelihood of exploitation as “Exploitation Unlikely,” and confirmed that the vulnerability has not been publicly exploited. However, organizations should still stay alert to potential threats.

The vulnerability was discovered and reported by an anonymous security researcher, whose contribution has been recognized in Microsoft’s security bulletin.

Organizations using Active Directory Certificate Services are urged to apply the necessary updates as part of their routine patch management procedures.

More Articles & Posts