CVE-2018-8340HighCVSS 6.5
ADFS Security Feature Bypass Vulnerability
🔗 CVE IDs covered (1)
📋 Description
A security feature bypass vulnerability exists when Active Directory Federation Services (ADFS) improperly handles multi-factor authentication requests. To exploit this vulnerability, an attacker could send a specially crafted authentication request. An attacker who successfully exploited this vulnerability could bypass some, but not all, of the authentication factors. This security update corrects how ADFS handles multi-factor authentication requests.
🎯 Affected products6
- Windows Server 2012 R2
- Windows Server 2012 R2 (Server Core installation)
- Windows Server 2016
- Windows Server 2016 (Server Core installation)
- Windows Server, version 1709 (Server Core Installation)
- Windows Server, version 1803 (Server Core Installation)
✅ Remediation
KB4343909 (Security Update) KB4343897 (Security Update) KB4343887 (Security Update) KB4343898 (Monthly Rollup) KB4343888 (Security Only)
🔗 References (6)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2018-8340
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4343909
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4343897
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4343887
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4343898
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4343888