CVE-2025-29968Improper Input Validation in Microsoft Windows Server 2008 R2 Service Pack 1

Severity
6.5MEDIUMNVD
EPSS
6.3%
top 9.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 13

Description

Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages8 packages

CVEListV5microsoft/windows_server_2008_service_pack_26.0.6003.06.0.6003.23279
CVEListV5microsoft/windows_server_2008_r2_service_pack_16.1.7601.06.1.7601.27729
NVDmicrosoft/windows< 10.0.14393.8066+4
CVEListV5microsoft/windows_server_20126.2.9200.06.2.9200.25475
CVEListV5microsoft/windows_server_201610.0.14393.010.0.14393.8066

🔴Vulnerability Details

2
GHSA
GHSA-xvfx-x2hm-pgf5: Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a network2025-05-13
CVEList
Active Directory Certificate Services (AD CS) Denial of Service Vulnerability2025-05-13

📋Vendor Advisories

2
Microsoft
Active Directory Certificate Services (AD CS) Denial of Service Vulnerability2025-05-13
Microsoft
An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private.2022-05-10

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws2025-05-13
CVE-2025-29968 — Improper Input Validation in Microsoft | cvebase