CVE-2018-8340HighCVSS 6.5

ADFS Security Feature Bypass Vulnerability

Published
August 14, 2018
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

A security feature bypass vulnerability exists when Active Directory Federation Services (ADFS) improperly handles multi-factor authentication requests. To exploit this vulnerability, an attacker could send a specially crafted authentication request. An attacker who successfully exploited this vulnerability could bypass some, but not all, of the authentication factors. This security update corrects how ADFS handles multi-factor authentication requests.

🎯 Affected products6

  • Windows Server 2012 R2
  • Windows Server 2012 R2 (Server Core installation)
  • Windows Server 2016
  • Windows Server 2016 (Server Core installation)
  • Windows Server, version 1709 (Server Core Installation)
  • Windows Server, version 1803 (Server Core Installation)

✅ Remediation

KB4343909 (Security Update) KB4343897 (Security Update) KB4343887 (Security Update) KB4343898 (Monthly Rollup) KB4343888 (Security Only)

🔗 References (6)