Описание
Windows AD FS Security Feature Bypass Vulnerability
FAQ
What kind of security feature could be bypassed by successfully exploiting this vulnerability?
This vulnerability could allow an attacker to bypass ADFS BannedIPList entries for WS-Trust workflows.
Обновления
Продукт | Статья | Обновление |
---|---|---|
Windows Server 2019 | ||
Windows Server 2019 (Server Core installation) | ||
Windows Server, version 2004 (Server Core installation) | ||
Windows Server, version 20H2 (Server Core Installation) | ||
Windows Server 2022 | ||
Windows Server 2022 (Server Core installation) |
Показывать по
10
Возможность эксплуатации
Publicly Disclosed
No
Exploited
No
Latest Software Release
Exploitation Less Likely
Older Software Release
Exploitation Less Likely
DOS
N/A
EPSS
Процентиль: 78%
0.01264
Низкий
5.3 Medium
CVSS3
Связанные уязвимости
CVSS3: 7.5
github
около 3 лет назад
Windows AD FS Security Feature Bypass Vulnerability
CVSS3: 5.3
fstec
больше 3 лет назад
Уязвимость службы Active Directory Federation Services (AD FS) операционной системы Windows, позволяющая нарушителю обойти механизм защиты
EPSS
Процентиль: 78%
0.01264
Низкий
5.3 Medium
CVSS3