CyberICT

CVE-2026-56155

Microsoft · Published July 14, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

Affected Products

  • Windows 10 1607 < 10.0.14393.9339
  • Windows 10 1809 < 10.0.17763.9020
  • Windows Server 2012
  • Windows Server 2016 < 10.0.14393.9339

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H