Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7f55-8m7r-49x9

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

A security feature bypass vulnerability exists in Active Directory Federation Services (ADFS) which could allow an attacker to bypass the extranet lockout policy.To exploit this vulnerability, an attacker could run a specially crafted application, which would allow an attacker to launch a password brute-force attack or cause account lockouts in Active Directory.This security update corrects how ADFS handles external authentication requests., aka 'ADFS Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0975.

A security feature bypass vulnerability exists in Active Directory Federation Services (ADFS) which could allow an attacker to bypass the extranet lockout policy.To exploit this vulnerability, an attacker could run a specially crafted application, which would allow an attacker to launch a password brute-force attack or cause account lockouts in Active Directory.This security update corrects how ADFS handles external authentication requests., aka 'ADFS Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0975.

EPSS

Процентиль: 83%
0.02074
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-307

Связанные уязвимости

CVSS3: 5.3
nvd
почти 6 лет назад

A security feature bypass vulnerability exists in Active Directory Federation Services (ADFS) which could allow an attacker to bypass the extranet lockout policy.To exploit this vulnerability, an attacker could run a specially crafted application, which would allow an attacker to launch a password brute-force attack or cause account lockouts in Active Directory.This security update corrects how ADFS handles external authentication requests., aka 'ADFS Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0975.

CVSS3: 5.3
msrc
почти 6 лет назад

ADFS Security Feature Bypass Vulnerability

CVSS3: 5.3
fstec
почти 6 лет назад

Уязвимость службы Active Directory Federation Services (AD FS) операционной системы Windows, позволяющая нарушителю обойти политику блокировки экстрасети AD FS

EPSS

Процентиль: 83%
0.02074
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-307