CVE-2021-36949HighCVSS 7.1

Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability

Published
August 10, 2021
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

What should I do to be protected against this vulnerability? In addition to applying the updates in this CVE, you will need to disable NTLM as per the guidance as follows: For Azure Active Directory Connect, see Prerequisites for Azure AD Connect For Azure Active Directory Connect Provisioning Agent, see Prerequisites for Azure AD Connect cloud sync What must an attacker do to exploit this vulnerability The attacker must be able to establish Man-in-the-middle between your Azure AD Connect server and a domain controller. The attacker also needs to possess domain user credentials to be able to exploit this vulnerability.

🎯 Affected products3

  • Azure Active Directory Connect Provisioning Agent
  • Microsoft Azure Active Directory Connect 1.X.Y.Z
  • Microsoft Azure Active Directory Connect 2.0.X.Y

✅ Remediation

KBRelease Notes (Security Update) — fixed build 1.6.11.3 KBRelease Notes (Security Update) — fixed build 1.1.582.0 KBRelease Notes (Security Update) — fixed build 2.0.8.0

🔗 References (6)