Количество 4
Количество 4

CVE-2019-1172
An information disclosure vulnerability exists in Azure Active Directory (AAD) Microsoft Account (MSA) during the login request session. An attacker who successfully exploited the vulnerability could take over a user's account. To exploit the vulnerability, an attacker would have to trick a user into browsing to a specially crafted website, allowing the attacker to steal the user's token. The security update addresses the vulnerability by correcting how MSA handles cookies.

CVE-2019-1172
Windows Information Disclosure Vulnerability
GHSA-2x5x-xqr8-2jhv
An information disclosure vulnerability exists in Azure Active Directory (AAD) Microsoft Account (MSA) during the login request session, aka 'Windows Information Disclosure Vulnerability'.

BDU:2019-02986
Уязвимость облачной службы управления удостоверениями и доступом Azure Active Directory (AAD) операционной системы Windows, позволяющая нарушителю получить доступ к учетной записи пользователя
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2019-1172 An information disclosure vulnerability exists in Azure Active Directory (AAD) Microsoft Account (MSA) during the login request session. An attacker who successfully exploited the vulnerability could take over a user's account. To exploit the vulnerability, an attacker would have to trick a user into browsing to a specially crafted website, allowing the attacker to steal the user's token. The security update addresses the vulnerability by correcting how MSA handles cookies. | CVSS3: 4.3 | 7% Низкий | почти 6 лет назад |
![]() | CVE-2019-1172 Windows Information Disclosure Vulnerability | CVSS3: 4.3 | 7% Низкий | почти 6 лет назад |
GHSA-2x5x-xqr8-2jhv An information disclosure vulnerability exists in Azure Active Directory (AAD) Microsoft Account (MSA) during the login request session, aka 'Windows Information Disclosure Vulnerability'. | CVSS3: 4.3 | 7% Низкий | около 3 лет назад | |
![]() | BDU:2019-02986 Уязвимость облачной службы управления удостоверениями и доступом Azure Active Directory (AAD) операционной системы Windows, позволяющая нарушителю получить доступ к учетной записи пользователя | CVSS3: 4.3 | 7% Низкий | почти 6 лет назад |
Уязвимостей на страницу