Количество 4
Количество 4
CVE-2019-1172
An information disclosure vulnerability exists in Azure Active Directory (AAD) Microsoft Account (MSA) during the login request session. An attacker who successfully exploited the vulnerability could take over a user's account. To exploit the vulnerability, an attacker would have to trick a user into browsing to a specially crafted website, allowing the attacker to steal the user's token. The security update addresses the vulnerability by correcting how MSA handles cookies.
CVE-2019-1172
Windows Information Disclosure Vulnerability
GHSA-2x5x-xqr8-2jhv
An information disclosure vulnerability exists in Azure Active Directory (AAD) Microsoft Account (MSA) during the login request session, aka 'Windows Information Disclosure Vulnerability'.
BDU:2019-02986
Уязвимость облачной службы управления удостоверениями и доступом Azure Active Directory (AAD) операционной системы Windows, позволяющая нарушителю получить доступ к учетной записи пользователя
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-1172 An information disclosure vulnerability exists in Azure Active Directory (AAD) Microsoft Account (MSA) during the login request session. An attacker who successfully exploited the vulnerability could take over a user's account. To exploit the vulnerability, an attacker would have to trick a user into browsing to a specially crafted website, allowing the attacker to steal the user's token. The security update addresses the vulnerability by correcting how MSA handles cookies. | CVSS3: 4.3 | 7% Низкий | около 6 лет назад | |
CVE-2019-1172 Windows Information Disclosure Vulnerability | CVSS3: 4.3 | 7% Низкий | около 6 лет назад | |
GHSA-2x5x-xqr8-2jhv An information disclosure vulnerability exists in Azure Active Directory (AAD) Microsoft Account (MSA) during the login request session, aka 'Windows Information Disclosure Vulnerability'. | CVSS3: 4.3 | 7% Низкий | больше 3 лет назад | |
BDU:2019-02986 Уязвимость облачной службы управления удостоверениями и доступом Azure Active Directory (AAD) операционной системы Windows, позволяющая нарушителю получить доступ к учетной записи пользователя | CVSS3: 4.3 | 7% Низкий | около 6 лет назад |
Уязвимостей на страницу