CVE-2019-0975HighCVSS 4.3

ADFS Security Feature Bypass Vulnerability

Published
July 9, 2019
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

A security feature bypass vulnerability exists when Active Directory Federation Services (ADFS) improperly updates its list of banned IP addresses. To exploit this vulnerability, an attacker would have to convince a victim ADFS administrator to update the list of banned IP addresses. This security update corrects how ADFS updates its list of banned IP addresses.

🎯 Affected products6

  • Windows Server 2016
  • Windows Server 2016 (Server Core installation)
  • Windows Server 2019
  • Windows Server 2019 (Server Core installation)
  • Windows Server, version 1803 (Server Core Installation)
  • Windows Server, version 1903 (Server Core installation)

✅ Remediation

KB4507435 (Security Update) KB4507469 (Security Update) KB4507460 (Security Update) KB4507453 (Security Update)

🔗 References (9)