CVE-2015-1638

Microsoft Active Directory Federation Services (AD FS) 3.0 on Windows Server 2012 R2 does not properly handle logoff actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation, aka "Active Directory Federation Services Information Disclosure Vulnerability."
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:datacenter:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:essentials:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:standard:*:*:*

History

21 Nov 2024, 02:25

Type Values Removed Values Added
References () http://www.securitytracker.com/id/1032115 - () http://www.securitytracker.com/id/1032115 -
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-040 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-040 -

Information

Published : 2015-04-14 20:59

Updated : 2024-11-21 02:25


NVD link : CVE-2015-1638

Mitre link : CVE-2015-1638

CVE.ORG link : CVE-2015-1638


JSON object : View

Products Affected

microsoft

  • windows_server_2012
CWE
CWE-264

Permissions, Privileges, and Access Controls