{"id":3940,"date":"2025-05-14T10:03:27","date_gmt":"2025-05-14T10:03:27","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/05\/14\/microsoft-warns-of-ad-cs-vulnerability-let-attackers-deny-service-over-a-network\/"},"modified":"2025-05-14T10:03:27","modified_gmt":"2025-05-14T10:03:27","slug":"microsoft-warns-of-ad-cs-vulnerability-let-attackers-deny-service-over-a-network","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/05\/14\/microsoft-warns-of-ad-cs-vulnerability-let-attackers-deny-service-over-a-network\/","title":{"rendered":"Microsoft Warns of AD CS Vulnerability Let Attackers Deny Service Over a Network"},"content":{"rendered":"<p>    Microsoft Warns of AD CS Vulnerability Let Attackers Deny Service Over a Network<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Microsoft has issued a security advisory regarding a new vulnerability in <a href=\"https:\/\/cybersecuritynews.com\/windows-remote-management-leveraged\/\" target=\"_blank\" rel=\"noreferrer noopener\">Active Directory<\/a> Certificate Services (AD CS) that could allow attackers to perform denial-of-service attacks over a network.\u00a0<\/p>\n<p>The vulnerability, identified as CVE-2025-29968, affects multiple versions of Windows Server and has been assigned an \u201cImportant\u201d severity rating with a CVSS score of 6.5\/5.7.<\/p>\n<p>The security flaw stems from improper input validation in Active Directory Certificate Services, a critical Windows role that enables organizations to issue and manage digital certificates for internal security purposes.\u00a0<\/p>\n<h2 class=\"wp-block-heading\"><strong>Microsoft AD CS Improper Input Validation Flaw<\/strong><\/h2>\n<p>The issue is categorized under CWE-20, Microsoft\u2019s technical documentation indicates that \u201cImproper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a network\u201d.<\/p>\n<p>When exploited, attackers can cause the AD CS service to become unresponsive, potentially disrupting authentication processes, secure communications, and other certificate-dependent operations across an organization\u2019s infrastructure.<\/p>\n<p>According to Microsoft\u2019s security bulletin, the vulnerability in the CVSS vector string indicates that this vulnerability can be exploited over a network with low attack complexity and requires low privileges.\u00a0<\/p>\n<p>No <a href=\"https:\/\/cybersecuritynews.com\/trust-wallet-browser-extension-flaw\/\" target=\"_blank\" rel=\"noreferrer noopener\">user interaction<\/a> is necessary for exploitation, and while the vulnerability doesn\u2019t impact confidentiality or integrity , it can severely affect availability .<\/p>\n<p>Researchers note that this vulnerability is concerning because an authenticated attacker with relatively low privileges could potentially disrupt certificate services across an entire organization.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>Risk Factors<\/strong><\/td>\n<td><strong>Details<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Affected Products<\/td>\n<td>\u2013 Windows Server 2022 (including 23H2 Edition)\u00a0\u2013 Windows Server 2019\u00a0\u2013 Windows Server 2016\u00a0\u2013 Windows Server 2012\/2012 R2\u00a0\u2013 Windows Server 2008\/2008 R2\u00a0<\/td>\n<\/tr>\n<tr>\n<td>Impact<\/td>\n<td>Denial of Service (DoS) via AD CS service disruption\u00a0<\/td>\n<\/tr>\n<tr>\n<td>Exploit Prerequisites<\/td>\n<td>\u2013 Low-privileged authenticated access\u00a0\u2013 Active Directory Certificate Services (AD CS) role enabled\u00a0<\/td>\n<\/tr>\n<tr>\n<td>CVSS 3.1 Score<\/td>\n<td>6.5 (Important)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\"><strong>Affected Systems<\/strong><\/h2>\n<p>The vulnerability impacts multiple Windows Server versions, including:<\/p>\n<ul class=\"wp-block-list\">\n<li>Windows Server 2022 (including 23H2 Edition).<\/li>\n<li>Windows Server 2019.<\/li>\n<li>Windows Server 2016.<\/li>\n<li>Windows Server 2012\/2012 R2.<\/li>\n<li>Windows Server 2008\/2008 R2.<\/li>\n<\/ul>\n<p>Both standard and Server Core installations are affected, as detailed in Microsoft\u2019s advisory. The vulnerability specifically targets the AD CS role when enabled on these servers.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Patches Released<\/strong><\/h2>\n<p>Microsoft has <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2025-29968\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">released<\/a> security updates to address this vulnerability. IT administrators are advised to apply the appropriate patches based on their Windows Server version. For example:<\/p>\n<ul class=\"wp-block-list\">\n<li>Windows Server 2022: KB5058385 (Security Update 10.0.20348.3692).<\/li>\n<li>Windows Server 2019: KB5058392 (Security Update 10.0.17763.7314).<\/li>\n<li>Windows Server 2016: KB5058383 (Security Update 10.0.14393.8066).<\/li>\n<\/ul>\n<p>Microsoft has assessed the exploitability as \u201cExploitation Unlikely\u201d and confirmed that the vulnerability has not been publicly disclosed or exploited in the wild. Nevertheless, security teams should remain vigilant.<\/p>\n<p>The anonymous security researcher who discovered and reported this vulnerability through coordinated disclosure has been acknowledged by Microsoft in their security bulletin.<\/p>\n<p>Organizations utilizing Active Directory Certificate Services are advised to implement the relevant security updates as part of their regular <a href=\"https:\/\/cybersecuritynews.com\/patch-management-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">patch management<\/a> process.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><code>Arm your business against phishing &amp; <strong>suspicious artifacts\u00a0<\/strong> with top threat intelligence,\u00a0<a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=5-ways-ti&amp;utm_content=plans&amp;utm_term=140525\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">test TI Lookup with 50 trial requests<\/a>\u00a0<\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/microsoft-warns-of-ad-cs-vulnerability\/\">Microsoft Warns of AD CS Vulnerability Let Attackers Deny Service Over a Network<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/microsoft-warns-of-ad-cs-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft Warns of AD CS Vulnerability Let Attackers Deny Service Over a Network Microsoft has issued a security advisory regarding a new vulnerability in Active Directory Certificate Services (AD CS) that could allow attackers to perform denial-of-service attacks over a network.\u00a0 The vulnerability, identified as CVE-2025-29968, affects multiple versions of Windows Server and has been [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,158,131],"tags":[130],"class_list":["post-3940","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-microsoft","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3940"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=3940"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3940\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=3940"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=3940"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=3940"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}