CVE-2019-1126HighCVSS 5.3

ADFS Security Feature Bypass Vulnerability

Published
July 9, 2019
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

A security feature bypass vulnerability exists in Active Directory Federation Services (ADFS) which could allow an attacker to bypass the extranet lockout policy. To exploit this vulnerability, an attacker could run a specially crafted application, which would allow an attacker to launch a password brute-force attack or cause account lockouts in Active Directory. This security update corrects how ADFS handles external authentication requests.

🎯 Affected products8

  • Windows Server 2012 R2
  • Windows Server 2012 R2 (Server Core installation)
  • Windows Server 2016
  • Windows Server 2016 (Server Core installation)
  • Windows Server 2019
  • Windows Server 2019 (Server Core installation)
  • Windows Server, version 1803 (Server Core Installation)
  • Windows Server, version 1903 (Server Core installation)

✅ Remediation

KB4507435 (Security Update) KB4507469 (Security Update) KB4507453 (Security Update) KB4507460 (Security Update) KB4507448 (Monthly Rollup) KB4507457 (Security Only)

🔗 References (13)